SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A developer is writing a RESTful API for a new mobile application. The API needs to enforce access control based on the user's role (e.g., 'admin', 'user', 'guest'). If a user attempts to access a resource that they are not authorized for, the API should reject the request. Which authorization model is being implemented here?
- ADiscretionary Access Control (DAC)
- BRole-Based Access Control (RBAC)
- CMandatory Access Control (MAC)
- DAttribute-Based Access Control (ABAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) assigns permissions to roles, and users are assigned to roles. This model is ideal for enforcing access based on a user's functional role within an application, as described in the scenario.
Why the other options are wrong
- A. DAC allows the owner of a resource to grant or deny access, which is not based on predefined roles.
- C. MAC is a highly structured model based on security labels (sensitivity levels), typically found in high-security environments, not simply user roles.
- D. ABAC grants access based on a set of attributes (user, resource, environment), which is more granular than simple roles, though roles can be an attribute.
Role-Based Access Control (RBAC)
An access control model where permissions are associated with roles, and users are assigned to appropriate roles, thereby inheriting the permissions associated with those roles.
- Simplifies access management by grouping permissions.
- Widely used in enterprise applications due to its flexibility and scalability.
- Based on the principle of least privilege.
Memory trick: Access control guides who can do what and where.