SSCP Systems Security Certified PractitionerAccess ControlsHard

A system implements an access control matrix where each cell defines the permissions a specific subject has over a specific object. This matrix is directly managed by the system and can be quite granular, allowing for unique permissions for every subject-object pair. Which access control model is most closely associated with this implementation?

  1. AMandatory Access Control (MAC)
  2. BDiscretionary Access Control (DAC)
  3. CRole-Based Access Control (RBAC)
  4. DCapability-Based Access Control
Show answer & explanation

Correct answer: B. Discretionary Access Control (DAC)

An access control matrix is a fundamental concept used to represent permissions in various models, but it's most closely associated with Discretionary Access Control (DAC) due to its granular, subject-object pair focus where permissions can be set by resource owners. While MAC and RBAC can be represented by matrices, DAC's inherent flexibility in assigning specific permissions to specific users for specific objects aligns perfectly with a direct matrix implementation.

Why the other options are wrong

  • A. MAC uses security labels and clearance, which is a higher-level abstraction than direct matrix cells for every pair.
  • C. RBAC uses roles to simplify permissions, so a direct matrix for every subject-object pair would defeat its purpose.
  • D. Capability-Based Access Control focuses on 'capabilities' (tokens) that grant rights, rather than a centralized matrix defining all permissions.

Access Control Matrix

A table that defines the permissions that each subject (user or process) has over each object (file, resource) in a system.

  • Rows represent subjects, columns represent objects.
  • Cells contain the access rights (e.g., read, write, execute).
  • A conceptual model often implemented using access control lists (ACLs) or capability lists.

Memory trick: Matrix Magic: Every cell is a permission, owner's decision.

More Access Controls questions