SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium

A developer is writing a RESTful API for a new mobile application. The API needs to enforce access control based on the user's role (e.g., 'admin', 'user', 'guest'). If a user attempts to access a resource that they are not authorized for, the API should reject the request. Which authorization model is being implemented here?

  1. ADiscretionary Access Control (DAC)
  2. BRole-Based Access Control (RBAC)
  3. CMandatory Access Control (MAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: B. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions to roles, and users are assigned to roles. This model is ideal for enforcing access based on a user's functional role within an application, as described in the scenario.

Why the other options are wrong

  • A. DAC allows the owner of a resource to grant or deny access, which is not based on predefined roles.
  • C. MAC is a highly structured model based on security labels (sensitivity levels), typically found in high-security environments, not simply user roles.
  • D. ABAC grants access based on a set of attributes (user, resource, environment), which is more granular than simple roles, though roles can be an attribute.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with roles, and users are assigned to appropriate roles, thereby inheriting the permissions associated with those roles.

  • Simplifies access management by grouping permissions.
  • Widely used in enterprise applications due to its flexibility and scalability.
  • Based on the principle of least privilege.

Memory trick: Access control guides who can do what and where.

More Systems and Application Security questions