Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

A large pharmaceutical company needs to ensure that only specific individuals in their research and development department can view highly confidential drug formulas. Access should be controlled based on their job title and department, not individual user accounts directly. Which access control model is most appropriate for this requirement?

  1. AMandatory Access Control (MAC)
  2. BRole-Based Access Control (RBAC)
  3. CDiscretionary Access Control (DAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: B. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions to roles, and then users are assigned to those roles based on their job functions. This aligns perfectly with controlling access based on 'job title and department' rather than individual accounts.

Why the other options are wrong

  • A. MAC uses security labels (sensitivity/clearance) and is typically found in highly secure government or military systems.
  • C. DAC allows resource owners to grant/revoke access, which is not centralized or based on job function.
  • D. ABAC evaluates attributes (user, resource, environment) at runtime, which is more granular than needed and more complex than the 'job title/department' requirement suggests.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with specific roles, and users are granted access by being assigned to the appropriate roles. This simplifies access management by linking permissions to job functions.

  • Permissions assigned to roles, not individual users.
  • Users inherit permissions by assuming roles.
  • Simplifies access management for large organizations.

Memory trick: RBAC: Roles are like job descriptions, giving you the keys you need for your work.

More Describe the concepts of security, compliance, and identity questions