Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy
A company is implementing a new system for managing employee access to various internal applications. They want to categorize users into groups based on their job functions (e.g., 'HR Staff', 'Finance Team', 'IT Admins') and assign permissions to these groups rather than to individual users. This approach simplifies management and ensures consistency. Which identity concept is being applied?
- AAttribute-Based Access Control (ABAC)
- BMandatory Access Control (MAC)
- CDiscretionary Access Control (DAC)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Role-Based Access Control (RBAC)
Assigning permissions based on a user's role or group function, rather than individually, is the core principle of Role-Based Access Control (RBAC). This simplifies management and scales well.
Why the other options are wrong
- A. ABAC grants access based on a combination of attributes, not just predefined roles.
- B. MAC enforces strict, system-wide rules for access, often used in high-security environments, not simply group-based permissions.
- C. DAC allows resource owners to control access, which can be less centralized and consistent.
Role-Based Access Control (RBAC)
An access control mechanism where permissions are associated with roles, and users are assigned to roles.
- Simplifies access management.
- Ensures consistent permissions across users in the same role.
- Commonly used in enterprise environments.
Memory trick: Roles make access simple and organized.