Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A global software company maintains sensitive intellectual property. They need a security strategy that ensures only specific employees, based on their job function, can access certain code repositories. For example, only developers can access active development branches, while testers can only access staging environments. Which access control model is best suited for implementing this requirement?

  1. AMandatory Access Control (MAC)
  2. BDiscretionary Access Control (DAC)
  3. CRole-Based Access Control (RBAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: C. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions based on a user's role within an organization. The scenario explicitly states that access should be granted 'based on their job function' (e.g., developers, testers), which is the core principle of RBAC.

Why the other options are wrong

  • A. MAC uses strict security labels (e.g., top secret) and is typically found in highly secure government or military environments, not based on job functions directly.
  • B. DAC allows resource owners to grant access, which can be difficult to manage at scale for specific job functions.
  • D. ABAC grants access based on a combination of attributes (user, resource, environment), which is more granular than roles but less direct for 'job function' as the primary driver.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with roles, and users are assigned to appropriate roles based on their job function.

  • Simplifies access management by grouping permissions into roles.
  • Users inherit permissions from their assigned roles.
  • Widely used in enterprise environments for managing access at scale.

Memory trick: RBAC: Roles Rule Access Right.

More Describe the concepts of security, compliance, and identity questions