nerdexam
(ISC)2

SSCP · Question #49

The type of discretionary access control (DAC) that is based on an individual's identity is also called:

The correct answer is A. Identity-based Access control. An identity-based access control is a type of Discretionary Access Control (DAC) that is based on an individual's identity. DAC is good for low level security environment. The owner of the file decides who has access to If a user creates a file, he is the owner of that file. An…

Submitted by ashley.k· Apr 18, 2026Access Controls

Question

The type of discretionary access control (DAC) that is based on an individual's identity is also called:

Options

  • AIdentity-based Access control
  • BRule-based Access control
  • CNon-Discretionary Access Control
  • DLattice-based Access control

How the community answered

(42 responses)
  • A
    88% (37)
  • B
    2% (1)
  • C
    7% (3)
  • D
    2% (1)

Explanation

An identity-based access control is a type of Discretionary Access Control (DAC) that is based on an individual's identity. DAC is good for low level security environment. The owner of the file decides who has access to If a user creates a file, he is the owner of that file. An identifier for this user is placed in the file header and/or in an access control matrix within the operating system. Ownership might also be granted to a specific individual. For example, a manager for a certain department might be made the owner of the files and resources within her department. A system that uses discretionary access control (DAC) enables the owner of the resource to specify which subjects can access specific resources. This model is called discretionary because the control of access is based on the discretion of the owner. Many times department managers, or business unit managers , are the owners of the data within their specific department. Being the owner, they can specify who should have access and

Topics

#Access Control#DAC#Identity-based Access Control

Community Discussion

No community discussion yet for this question.

Full SSCP Practice