CISSP-ISSAP · Question #24
The network you administer allows owners of objects to manage the access to those objects via access control lists. This is an example of what type of access control?
The correct answer is D. DAC. DAC (Discretionary Access Control) is correct because it is defined by object owners having the authority to grant or restrict access to their own resources - typically implemented via access control lists (ACLs). The "discretionary" part means access decisions are left to the…
Question
The network you administer allows owners of objects to manage the access to those objects via access control lists. This is an example of what type of access control?
Options
- ARBAC
- BMAC
- CCIA
- DDAC
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C4% (1)
- D86% (24)
Explanation
DAC (Discretionary Access Control) is correct because it is defined by object owners having the authority to grant or restrict access to their own resources - typically implemented via access control lists (ACLs). The "discretionary" part means access decisions are left to the owner's discretion.
Why the distractors are wrong:
- A (RBAC) - Role-Based Access Control assigns permissions based on a user's role in the organization, not by individual owners managing their own objects.
- B (MAC) - Mandatory Access Control is enforced by the system/administrator using security labels and classifications (e.g., Top Secret); owners cannot override policy.
- C (CIA) - The CIA triad (Confidentiality, Integrity, Availability) is a security framework, not an access control model at all.
Memory tip: Think of DAC = "Discretion of the Data owner" - if the owner controls the locks, it's DAC. If the system/admin controls the locks, it's MAC.
Topics
Community Discussion
No community discussion yet for this question.