ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Hard

An organization is designing an access control system for a highly secure research laboratory. Access to the lab requires employees to use a smart card, enter a PIN, and pass a retina scan. Additionally, access is only granted during specific working hours and only if the employee's security clearance level matches the lab's classification. What type of access control, combining multiple factors and contextual rules, is being implemented?

  1. ARole-Based Access Control (RBAC) with Multi-Factor Authentication (MFA)
  2. BMandatory Access Control (MAC) with Attribute-Based Access Control (ABAC) enhancements
  3. CDiscretionary Access Control (DAC) with biometrics
  4. DContent-Based Access Control (CBAC) with Time-of-Day restrictions
Show answer & explanation

Correct answer: B. Mandatory Access Control (MAC) with Attribute-Based Access Control (ABAC) enhancements

The core requirement of 'security clearance level matches the lab's classification' is a hallmark of Mandatory Access Control (MAC), where the system enforces access based on sensitivity labels. The additional conditions like smart card + PIN + retina scan (MFA) and 'specific working hours' are contextual attributes typically associated with Attribute-Based Access Control (ABAC), which can enhance MAC by adding fine-grained, dynamic rules. The combination reflects a highly controlled environment with both label-based and attribute-based enforcement.

Why the other options are wrong

  • A. While MFA is present, RBAC alone doesn't account for 'security clearance level matches classification' as a primary access determinant, which is MAC's domain.
  • C. DAC allows owners to set permissions, which contradicts the rigid, system-enforced nature described by clearance levels and classification.
  • D. CBAC focuses on the content of the data, not the subject's clearance or environmental attributes for physical access. Time-of-Day is an attribute, but CBAC isn't the primary model here.

MAC with ABAC Enhancement

Combining Mandatory Access Control's label-based enforcement with Attribute-Based Access Control's dynamic, contextual rules for highly granular and secure access decisions.

  • MAC enforces strict 'need-to-know' based on classification.
  • ABAC adds flexibility with attributes like time, location, device, MFA status.
  • Used in high-security environments (e.g., military, intelligence).

Memory trick: MAC-ABAC: Mandatory Attributes Control All.

More Identity and Access Management (IAM) questions