Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A security auditor is reviewing an organization's access control mechanisms. The auditor notes that employees are granted access permissions based on their specific job functions and roles within the company, rather than individual user accounts having unique, granular permissions assigned manually. This approach ensures that employees only have the minimum necessary access to perform their duties. Which access control model is being described?

  1. AMandatory Access Control (MAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CRole-Based Access Control (RBAC)
  4. DDiscretionary Access Control (DAC)
Show answer & explanation

Correct answer: C. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) grants access permissions to users based on their assigned roles within an organization. This simplifies management and ensures that users only have the privileges necessary for their job functions.

Why the other options are wrong

  • A. MAC uses security labels (sensitivity levels) for strict, system-enforced access, typically in high-security environments.
  • B. ABAC grants access based on a combination of user, resource, and environmental attributes, which is more dynamic and complex than described.
  • D. DAC allows resource owners to define access, which is less structured than role-based assignments.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with specific roles, and users are granted access by being assigned to those roles.

  • Simplifies access management for large organizations.
  • Ensures least privilege by default based on job function.
  • Commonly used in enterprise environments.

Memory trick: RBAC: Roles get permissions, users get roles. Simple!

More Cybersecurity Fundamentals questions