nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #160

In a DAC policy scenario, which of these tasks can only be performed by a subject granted access to information?

The correct answer is C. Changing security attributes. As a principle, users can perform Read, Write and Execute actions with every Access Control policy. However, in discretionary access control policies, the permissions associated with each object (files or system resources) are set by the object's owner. In this model, the…

Access Control Concepts

Question

In a DAC policy scenario, which of these tasks can only be performed by a subject granted access to information?

Options

  • AModifying the information
  • BExecuting the information
  • CChanging security attributes
  • DReading the information

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    87% (33)
  • D
    5% (2)

Explanation

As a principle, users can perform Read, Write and Execute actions with every Access Control policy. However, in discretionary access control policies, the permissions associated with each object (files or system resources) are set by the object's owner. In this model, the creator of an object implicitly becomes its owner, and therefore can decide who will have permission to the objects (see ISC2 Study Guide, chapter 3, module 3). A major weakness of DAC is that it gives users complete control to set security level settings for other users, which can result in users having more privileges than they are supposed to.

Topics

#Discretionary Access Control (DAC)#Access Control Models#Permissions Management#Security Attributes

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice