CISSP-ISSAP · Question #120
You work as an administrator for Techraft Inc. Employees of your company create 'products', which are supposed to be given different levels of access. You need to configure a security policy in such…
The correct answer is A. Discretionary access control (DAC). Discretionary Access Control (DAC) is correct because it places access decisions in the hands of the resource owner - in this case, the employee who created the product. DAC allows owners to grant or revoke permissions (read, write, alter) to other users at their own…
Question
You work as an administrator for Techraft Inc. Employees of your company create 'products', which are supposed to be given different levels of access. You need to configure a security policy in such a way that an employee (producer of the product) grants accessing privileges (such as read, write, or alter) for his product. Which of the following access control models will you use to accomplish this task?
Options
- ADiscretionary access control (DAC)
- BRole-based access control (RBAC)
- CMandatory access control (MAC)
- DAccess control list (ACL)
How the community answered
(37 responses)- A81% (30)
- B5% (2)
- C3% (1)
- D11% (4)
Explanation
Discretionary Access Control (DAC) is correct because it places access decisions in the hands of the resource owner - in this case, the employee who created the product. DAC allows owners to grant or revoke permissions (read, write, alter) to other users at their own discretion, which is exactly what the scenario describes.
RBAC (B) is wrong because access is determined by a user's organizational role (e.g., Manager, Developer), not by the individual resource creator - an admin assigns roles, not the product owner.
MAC (C) is wrong because access is governed by a central authority using classification labels (e.g., Top Secret, Unclassified); the resource owner has no power to grant privileges themselves.
ACL (D) is wrong because an Access Control List is an implementation mechanism used to enforce access control - it is not an access control model in itself, and it can underpin DAC, MAC, or RBAC.
Memory tip: Think of DAC = "Discretion of the data owner." Whenever you see a scenario where the creator/owner personally hands out permissions, that's DAC.
Topics
Community Discussion
No community discussion yet for this question.