Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard

A security auditor is reviewing a company's network security posture and identifies a critical vulnerability: the network does not enforce any policy-based access control, meaning any authenticated user can access any resource. The auditor recommends implementing a system that defines and enforces access rights based on user roles, attributes, and environmental conditions. Which security model is being recommended?

  1. ARole-Based Access Control (RBAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CDiscretionary Access Control (DAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: B. Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is a flexible model that grants access based on a combination of user attributes (e.g., department, clearance), resource attributes (e.g., sensitivity, owner), and environmental conditions (e.g., time of day, location). This aligns with the need for policy-based access rights based on roles, attributes, and environmental conditions.

Why the other options are wrong

  • A. RBAC grants access based on predefined roles, which is a component of the requirement but doesn't include 'attributes and environmental conditions'.
  • C. DAC allows resource owners to define access, which is too permissive for this scenario.
  • D. MAC enforces access based on security labels (e.g., top secret), often used in highly secure environments, but less flexible than ABAC for 'roles, attributes, and environmental conditions'.

Attribute-Based Access Control (ABAC)

An authorization model that grants or denies access to resources based on a set of attributes associated with the user, resource, and environmental conditions.

  • Highly granular and flexible access control.
  • Uses attributes for user, resource, and environment.
  • Evaluates policies dynamically at the time of access.
  • Goes beyond roles to provide more context-aware access.

Memory trick: ABAC: Access is based on 'A'll the 'B'its 'A'bout 'C'ontext.

More Network Security questions