Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy

A small business is exploring options to protect its sensitive customer database from unauthorized access. They need a solution that simplifies access management for employees based on their job roles, ensuring that only authorized personnel can view or modify specific records. Which security model would best fit this requirement?

  1. ARole-Based Access Control (RBAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CMandatory Access Control (MAC)
  4. DDiscretionary Access Control (DAC)
Show answer & explanation

Correct answer: A. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions based on an individual's job function or role within an organization, making it ideal for managing access to resources like a customer database.

Why the other options are wrong

  • B. ABAC grants access based on various attributes, which is more complex than 'job roles' alone.
  • C. MAC enforces strict, system-wide access policies, often too rigid for typical business needs.
  • D. DAC allows resource owners to define access, which can be difficult to manage at scale.

Role-Based Access Control (RBAC)

A security model where access permissions are assigned to roles, and users are assigned to roles, simplifying access management based on job functions.

  • Permissions granted based on user's role.
  • Simplifies access management for large organizations.
  • Commonly used in enterprise environments.

Memory trick: Roles make access simple, like a job description.

More Cybersecurity Fundamentals questions