SSCP Systems Security Certified PractitionerAccess ControlsEasy

A security administrator is configuring access for a new network-attached storage (NAS) device. The policy states that only members of the 'Finance' group should have read and write access to the 'Budgets' share, while all other authenticated users should have no access. Which of the following access control models is being primarily implemented?

  1. ADiscretionary Access Control (DAC)
  2. BMandatory Access Control (MAC)
  3. CRole-Based Access Control (RBAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: C. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions to roles, and users are then assigned to roles. In this scenario, access is determined by membership in the 'Finance' group, which functions as a role.

Why the other options are wrong

  • A. DAC allows resource owners to define access, which is not the primary method described here.
  • B. MAC enforces access based on sensitivity labels, which is not mentioned in the scenario.
  • D. ABAC grants access based on attributes of the user, resource, and environment, which is more dynamic and granular than group membership alone.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with roles, and users are assigned to appropriate roles based on their job functions.

  • Simplifies access management for large organizations.
  • Users are not directly assigned permissions, but acquire them through roles.
  • Commonly used in enterprise environments.

Memory trick: Roles make access simple and strong, like a well-organized team.

More Access Controls questions