ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A cybersecurity team is evaluating a new authentication system. They want to ensure that once a user's identity is verified, their access to specific resources is appropriately granted or denied based on their roles and permissions. Which security service is being addressed here?
- AAuthentication
- BAuthorization
- CAccounting
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: B. Authorization
Authorization determines what an authenticated user is permitted to do, which aligns with granting or denying access based on roles and permissions.
Why the other options are wrong
- A. Authentication verifies a user's identity, which happens before authorization.
- C. Accounting tracks user actions and resource consumption.
- D. Availability ensures systems and data are accessible when needed.
Authorization
The process of determining what an authenticated entity is permitted to do or access within a system.
- Happens after authentication.
- Based on roles, permissions, and access control policies.
- Controls access to specific resources and functions.
Memory trick: AAA: Authenticate (who are you?), Authorize (what can you do?), Account (what did you do?).