nerdexam
(ISC)2

CISSP-ISSAP · Question #202

Which of the following are the primary components of a discretionary access control (DAC) model? Each correct answer represents a complete solution. Choose two.

The correct answer is B. File and data ownership D. Access rights and permissions. Discretionary Access Control (DAC) revolves around two core pillars: file and data ownership (B) determines who controls a resource, and access rights and permissions (D) define what operations are allowed on it. In DAC, the owner of a resource has discretion to grant or revoke…

Identity and Access Management (IAM) Architecture

Question

Which of the following are the primary components of a discretionary access control (DAC) model? Each correct answer represents a complete solution. Choose two.

Options

  • AUser's group
  • BFile and data ownership
  • CSmart card
  • DAccess rights and permissions

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    83% (24)
  • C
    14% (4)

Explanation

Discretionary Access Control (DAC) revolves around two core pillars: file and data ownership (B) determines who controls a resource, and access rights and permissions (D) define what operations are allowed on it. In DAC, the owner of a resource has discretion to grant or revoke access to others - ownership and permission assignment are inseparable from the model's definition.

Why the distractors are wrong:

  • A (User's group): Groups are an implementation mechanism used in many systems, but they are not a defining component of DAC itself - DAC is owner-centric, not group-centric. Groups are more fundamental to Role-Based Access Control (RBAC).
  • C (Smart card): Smart cards are an authentication technology (something-you-have factor), completely unrelated to the access control model itself.

Memory tip: Think of DAC as "the owner decides" - you need an owner (B) and rules the owner can set (D). If the answer doesn't relate to ownership or permission assignment, it's not a DAC primary component.

Topics

#Discretionary Access Control#File Ownership#User Permissions#Access Control Models

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice