nerdexam
(ISC)2

CISSP-ISSAP · Question #121

Which of the following decides access control on an object in the mandatory access control (MAC) environment?

The correct answer is A. Sensitivity label. In a MAC environment, sensitivity labels (also called security labels) are the mechanism that determines access control - the system compares the subject's clearance label to the object's sensitivity label to decide whether access is permitted, with no discretion left to the…

Identity and Access Management (IAM) Architecture

Question

Which of the following decides access control on an object in the mandatory access control (MAC) environment?

Options

  • ASensitivity label
  • BEvent log
  • CSystem Access Control List (SACL)
  • DSecurity log

How the community answered

(63 responses)
  • A
    89% (56)
  • B
    6% (4)
  • C
    3% (2)
  • D
    2% (1)

Explanation

In a MAC environment, sensitivity labels (also called security labels) are the mechanism that determines access control - the system compares the subject's clearance label to the object's sensitivity label to decide whether access is permitted, with no discretion left to the object owner. Option B (Event log) records system activity for auditing purposes but has no role in access decisions. Option C (SACL) is part of Windows ACL architecture and controls auditing (which access attempts get logged), not access enforcement - it lives in the discretionary/audit world, not MAC. Option D (Security log) is simply where those SACL-triggered audit events are written, making it equally irrelevant to access decisions.

Memory tip: Think "MAC = Label controls all" - in MAC, labels are mandatory and immutable by users, which is exactly what distinguishes it from DAC (where owners set permissions). If you see "MAC + access decision," the answer involves labels.

Topics

#Mandatory Access Control#Sensitivity Labels#Access Decision Mechanism#Security Classification

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice