Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard

A cybersecurity consultant is advising a government agency on protecting highly classified information. The agency requires an access control model that enforces strict, non-discretionary rules based on sensitivity labels, where subjects and objects are assigned security clearances and classifications, respectively. Which access control model should the consultant recommend?

  1. AAttribute-Based Access Control (ABAC)
  2. BDiscretionary Access Control (DAC)
  3. CMandatory Access Control (MAC)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: C. Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is the most suitable model for environments requiring strict, non-discretionary access based on sensitivity labels (security clearances and classifications), commonly used in government and military settings.

Why the other options are wrong

  • A. ABAC uses attributes for granular control but doesn't inherently provide the strict, non-discretionary, label-based enforcement required for classified environments as directly as MAC.
  • B. DAC allows data owners to define access, which is too flexible for highly classified information.
  • D. RBAC grants access based on job roles, but doesn't inherently enforce strict sensitivity labels or non-discretionary access.

Mandatory Access Control (MAC)

An access control model where the operating system or security kernel enforces access rules based on security labels (sensitivity levels) assigned to subjects (users/processes) and objects (files/resources).

  • Non-discretionary: Users cannot override access rules.
  • Commonly used in highly secure environments (e.g., military, government).
  • Employs a lattice-based model for security clearances/classifications.

Memory trick: The system mandates access, not the user.

More Cybersecurity Fundamentals questions