Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard
A cybersecurity consultant is advising a government agency on protecting highly classified information. The agency requires an access control model that enforces strict, non-discretionary rules based on sensitivity labels, where subjects and objects are assigned security clearances and classifications, respectively. Which access control model should the consultant recommend?
- AAttribute-Based Access Control (ABAC)
- BDiscretionary Access Control (DAC)
- CMandatory Access Control (MAC)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Mandatory Access Control (MAC)
Mandatory Access Control (MAC) is the most suitable model for environments requiring strict, non-discretionary access based on sensitivity labels (security clearances and classifications), commonly used in government and military settings.
Why the other options are wrong
- A. ABAC uses attributes for granular control but doesn't inherently provide the strict, non-discretionary, label-based enforcement required for classified environments as directly as MAC.
- B. DAC allows data owners to define access, which is too flexible for highly classified information.
- D. RBAC grants access based on job roles, but doesn't inherently enforce strict sensitivity labels or non-discretionary access.
Mandatory Access Control (MAC)
An access control model where the operating system or security kernel enforces access rules based on security labels (sensitivity levels) assigned to subjects (users/processes) and objects (files/resources).
- Non-discretionary: Users cannot override access rules.
- Commonly used in highly secure environments (e.g., military, government).
- Employs a lattice-based model for security clearances/classifications.
Memory trick: The system mandates access, not the user.