Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy

A security auditor is reviewing the access control implementation for a cloud-based data lake containing sensitive customer information. The auditor notes that access policies are defined based on the user's role (e.g., 'data analyst', 'developer', 'auditor') and their specific job functions, granting only the necessary permissions to perform their tasks. Which access control model is being utilized?

  1. AMandatory Access Control (MAC)
  2. BDiscretionary Access Control (DAC)
  3. CAttribute-Based Access Control (ABAC)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: D. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions to users based on their organizational role, granting access to resources based on the permissions associated with that role, which directly matches the scenario described.

Why the other options are wrong

  • A. MAC enforces access based on security labels (e.g., top secret), not user roles/job functions.
  • B. DAC allows resource owners to define access, which is not the primary mechanism described.
  • C. ABAC grants access based on a set of attributes (user, resource, environment), which is more granular than just roles.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with specific roles, and users are assigned to roles, thereby inheriting the permissions of those roles.

  • Simplifies access management by grouping permissions into roles.
  • Users gain permissions by being assigned to roles.
  • Widely used in cloud environments for managing access to resources.

Memory trick: RBAC: If you have the 'R'ole, you get the 'B'enefits of 'AC'cess.

More Cloud Security questions