nerdexam
(ISC)2

CISSP-ISSAP · Question #24

The network you administer allows owners of objects to manage the access to those objects via access control lists. This is an example of what type of access control?

The correct answer is D. DAC. DAC (Discretionary Access Control) is correct because it is defined by object owners having the authority to grant or restrict access to their own resources - typically implemented via access control lists (ACLs). The "discretionary" part means access decisions are left to the…

Identity and Access Management (IAM) Architecture

Question

The network you administer allows owners of objects to manage the access to those objects via access control lists. This is an example of what type of access control?

Options

  • ARBAC
  • BMAC
  • CCIA
  • DDAC

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    4% (1)
  • D
    86% (24)

Explanation

DAC (Discretionary Access Control) is correct because it is defined by object owners having the authority to grant or restrict access to their own resources - typically implemented via access control lists (ACLs). The "discretionary" part means access decisions are left to the owner's discretion.

Why the distractors are wrong:

  • A (RBAC) - Role-Based Access Control assigns permissions based on a user's role in the organization, not by individual owners managing their own objects.
  • B (MAC) - Mandatory Access Control is enforced by the system/administrator using security labels and classifications (e.g., Top Secret); owners cannot override policy.
  • C (CIA) - The CIA triad (Confidentiality, Integrity, Availability) is a security framework, not an access control model at all.

Memory tip: Think of DAC = "Discretion of the Data owner" - if the owner controls the locks, it's DAC. If the system/admin controls the locks, it's MAC.

Topics

#Discretionary Access Control#Access Control Lists#Authorization

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice