SSCP Systems Security Certified PractitionerAccess ControlsMedium
A network engineer is configuring a firewall to allow specific traffic. The policy states that only traffic from the internal 'Web Servers' subnet (192.168.10.0/24) should be allowed to access the external 'DMZ Database' server (172.16.1.50) on port 3306. All other traffic to this database server should be denied. What type of authorization mechanism is primarily being used?
- AAccess Control List (ACL)
- BRule-Based Access Control (RBAC)
- CDiscretionary Access Control (DAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Access Control List (ACL)
An Access Control List (ACL) is a list of permissions attached to an object (like a network interface or a file) that specifies which users or system processes are granted access to the object, and what operations are allowed on it. In networking, ACLs are used by firewalls and routers to filter traffic based on rules like source/destination IP, port, and protocol.
Why the other options are wrong
- B. RBAC assigns permissions to roles, which is for user access to resources, not network traffic filtering.
- C. DAC is user-centric and allows resource owners to set permissions, which is not how firewalls operate.
- D. MAC is label-based and typically used in high-security environments, not for basic network traffic filtering.
Access Control List (ACL)
A list of entries, typically associated with an object, that specifies which subjects are granted or denied access to the object and what operations they can perform.
- Used extensively in networking (firewalls, routers) and operating systems.
- Each entry (ACE) defines a subject, an object, and a set of permissions.
- Can be stateless (packet filtering) or stateful (firewall).
Memory trick: ACLs are like bouncers at the network club, checking IDs.