SSCP Systems Security Certified PractitionerAccess ControlsMedium

A system administrator is configuring a new file server. They decide that instead of assigning individual permissions to each user, they will create groups based on departments (e.g., 'Finance', 'HR', 'IT') and assign permissions to these groups. Users will then be added to the appropriate department group. Which access control model is this administrator implementing?

  1. ARole-Based Access Control (RBAC)
  2. BMandatory Access Control (MAC)
  3. CRule-Based Access Control
  4. DDiscretionary Access Control (DAC)
Show answer & explanation

Correct answer: A. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions to roles, and then users are assigned to those roles. In this scenario, 'department groups' function as roles, and permissions are assigned to these groups, not directly to individual users.

Why the other options are wrong

  • B. MAC relies on security labels and clearance levels, which is not described in the scenario.
  • C. Rule-Based Access Control uses specific rules (e.g., 'deny all traffic from X IP') rather than roles/groups for permissions.
  • D. DAC allows resource owners to set permissions, which is not the case here as an administrator is setting group permissions.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with roles, and users are assigned to appropriate roles based on their job functions.

  • Simplifies access management in large organizations.
  • Reduces administrative overhead compared to DAC.
  • Roles can be hierarchical or constrained.

Memory trick: Role-play Rules: Groups get permissions, users get groups.

More Access Controls questions