nerdexam
CompTIA

SY0-301 · Question #216

The IT department has setup a share point site to be used on the intranet. Security has established the groups and permissions on the site. No one may modify the permissions and all requests for…

The correct answer is D. Discretionary access control. Discretionary Access Control (DAC) is a model in which an owner or designated administrator has the discretion to determine who can access a resource and what level of access they receive. In this scenario, the security team acts as the owner/administrator and exercises…

Security operations

Question

The IT department has setup a share point site to be used on the intranet. Security has established the groups and permissions on the site. No one may modify the permissions and all requests for access are centrally managed by the security team. This is an example of which of the following control types?

Options

  • ARule based access control
  • BMandatory access control
  • CUser assigned privilege
  • DDiscretionary access control

How the community answered

(17 responses)
  • A
    12% (2)
  • B
    6% (1)
  • C
    6% (1)
  • D
    76% (13)

Explanation

Discretionary Access Control (DAC) is a model in which an owner or designated administrator has the discretion to determine who can access a resource and what level of access they receive. In this scenario, the security team acts as the owner/administrator and exercises discretionary control by managing all permissions centrally. The fact that end users cannot modify permissions simply means only the authorized administrator (security team) exercises that discretion. Mandatory Access Control (Option B) uses system-enforced labels and classifications, not just centralized administration. Rule-Based Access Control (Option A) relies on automated rules such as time of day or IP address. User Assigned Privilege (Option C) would imply users themselves assign or self-manage access, which is not the case here.

Topics

#discretionary access control#access control models#permission management#centralized security

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice