Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementEasy

A network security engineer is implementing an access control solution for critical server infrastructure. The solution must ensure that access is granted based on the user's role and departmental affiliation, rather than individual user accounts, and that these policies can be consistently applied across diverse network devices and operating systems. Which access control model is best suited for this requirement?

  1. AAttribute-Based Access Control (ABAC)
  2. BRole-Based Access Control (RBAC)
  3. CDiscretionary Access Control (DAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: B. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions based on a user's role within an organization, allowing for consistent policy application across multiple systems and aligning with departmental affiliations, which directly matches the requirements.

Why the other options are wrong

  • A. ABAC grants access based on a combination of attributes, which is more dynamic and complex than the role-based requirement specified.
  • C. DAC allows resource owners to define access, leading to inconsistent policies and management overhead.
  • D. MAC uses sensitivity labels and clearance levels, which is typically for highly secure government or military environments, not general corporate role-based access.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with roles, and users are assigned to roles, thereby inheriting the permissions of that role.

  • Simplifies access management for large organizations.
  • Ensures consistent application of access policies.
  • Roles typically align with job functions or departmental responsibilities.

Memory trick: DAC gives freedom, MAC enforces, RBAC structures, ABAC adapts.

More Visibility and Enforcement questions