SSCP Systems Security Certified PractitionerAccess ControlsMedium
A cloud service provider offers a service where customers can manage their own virtual machines. Each customer is responsible for setting permissions on their individual VMs and data within those VMs, determining who can access them and with what privileges. The provider enforces a base level of security but allows customers full control over their own resources. Which access control model is primarily demonstrated by the customer's ability to manage their own VM access?
- ADiscretionary Access Control (DAC)
- BRole-Based Access Control (RBAC)
- CAttribute-Based Access Control (ABAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Discretionary Access Control (DAC)
Discretionary Access Control (DAC) grants owners full control over their resources, allowing them to define and modify access permissions for other users. This aligns perfectly with customers managing permissions on their own VMs.
Why the other options are wrong
- B. RBAC assigns permissions based on predefined roles, not individual resource ownership.
- C. ABAC uses attributes for granular access decisions, but the core principle of owner control over permissions is DAC.
- D. MAC relies on system-enforced security labels, not owner discretion.
Discretionary Access Control (DAC)
An access control model where the owner of a resource determines who has access to it and what privileges they possess. Access decisions are at the discretion of the resource owner.
- Owners have full control over their resources.
- Common in many operating systems (e.g., file permissions).
- Can lead to complex permission sets and potential security vulnerabilities if not managed well.
Memory trick: DAC: Discretion is the Owner's Choice.