Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium
A security auditor is reviewing an organization's access control policies. The auditor notes that employees are granted access to resources based on their job functions and responsibilities within the company, rather than individually assigned permissions for every single resource. Which access control model is being utilized?
- AAttribute-Based Access Control (ABAC)
- BMandatory Access Control (MAC)
- CRole-Based Access Control (RBAC)
- DDiscretionary Access Control (DAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) assigns permissions to roles, and users are then assigned to roles based on their job functions, precisely matching the scenario described.
Why the other options are wrong
- A. ABAC grants access based on attributes (characteristics) of the user, resource, and environment, offering more granular control than RBAC.
- B. MAC is a highly structured model where access is determined by security labels (sensitivity levels) assigned to subjects and objects.
- D. DAC allows resource owners to control access to their resources.
Role-Based Access Control (RBAC)
An access control model where permissions are associated with roles, and users are assigned to appropriate roles based on their job functions or responsibilities.
- Simplifies access management in large organizations.
- Reduces the risk of excessive permissions.
- Roles are defined by job functions (e.g., 'Analyst', 'Manager').
Memory trick: Who gets in, and how do they prove it?