SSCP Systems Security Certified PractitionerAccess ControlsMedium

A security administrator is configuring access for a new human resources application. The policy states that only HR managers can approve leave requests, but only if the request is for an employee within their direct reporting structure and the requested leave period does not conflict with critical project deadlines. Which access control mechanism best describes this scenario?

  1. ARole-Based Access Control (RBAC)
  2. BDiscretionary Access Control (DAC)
  3. CMandatory Access Control (MAC)
  4. DContext-Based Access Control (CBAC)
Show answer & explanation

Correct answer: D. Context-Based Access Control (CBAC)

Context-Based Access Control (CBAC) evaluates not only the user's identity or role but also various environmental and situational attributes, such as time of day, location, or the specific details of the resource being accessed. In this scenario, access is determined by the user's role (HR manager), the employee's reporting structure, and project deadlines, which are all contextual factors.

Why the other options are wrong

  • A. RBAC grants access based on a user's role, but does not inherently incorporate dynamic contextual factors like reporting structure or project deadlines.
  • B. DAC allows the resource owner to define access, which is not the primary mechanism described here.
  • C. MAC enforces a system-wide policy based on sensitivity labels, which is not the mechanism described here.

Context-Based Access Control (CBAC)

An access control mechanism that grants or denies access based on the user's identity, attributes, and current environmental or situational factors.

  • Considers dynamic attributes like time, location, device, or resource state.
  • Provides granular and adaptive access decisions.
  • More flexible than static role or attribute-based models.

Memory trick: Access decisions depend on who, what, where, and when.

More Access Controls questions