ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

A cybersecurity team is evaluating a new authentication system. They want to ensure that once a user's identity is verified, their access to specific resources is appropriately granted or denied based on their roles and permissions. Which security service is being addressed here?

  1. AAuthentication
  2. BAuthorization
  3. CAccounting
  4. DAvailability
Show answer & explanation

Correct answer: B. Authorization

Authorization determines what an authenticated user is permitted to do, which aligns with granting or denying access based on roles and permissions.

Why the other options are wrong

  • A. Authentication verifies a user's identity, which happens before authorization.
  • C. Accounting tracks user actions and resource consumption.
  • D. Availability ensures systems and data are accessible when needed.

Authorization

The process of determining what an authenticated entity is permitted to do or access within a system.

  • Happens after authentication.
  • Based on roles, permissions, and access control policies.
  • Controls access to specific resources and functions.

Memory trick: AAA: Authenticate (who are you?), Authorize (what can you do?), Account (what did you do?).

More Security Principles questions