exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 217 discussion

Actual exam question from Cisco's 200-201
Question #: 217
Topic #: 1
[All 200-201 Questions]

What is the difference between discretionary access control (DAC) and role-based access control (RBAC)?

  • A. DAC administrators pass privileges to users and groups, and in RBAC, permissions are applied to specific groups.
  • B. DAC requires explicit authorization for a given user on a given object, RBAC requires specific conditions.
  • C. RBAC is an extended version of DAC where you can add an extra level of authorization based on time.
  • D. RBAC access is granted when a user meets specific conditions, and in DAC, permissions are applied on user and group levels.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sheyshey
6 days, 22 hours ago
Selected Answer: A
I'll go with A Feature DAC (Discretionary Access Control) RBAC (Role-Based Access Control) Focus Individual users and groups Roles and predefined conditions Permission assignment Administrators grant access directly to users and groups Permissions assigned to roles, users inherit permissions based on their assigned roles Flexibility Highly flexible, allows granular control over individual permissions Less flexible than DAC, but simplifies administration and reduces permission creep Example File system permissions, where users have specific read/write access to certain files and folders Network access control, where users are assigned roles like "administrator" or "editor" with predefined permissions
upvoted 1 times
...
Faio
3 months ago
The answer is D. DAC is a type of access control that allows the owner of an object to define who has access to it. Permissions are applied on a user and group level. For example, the owner of a file can grant read, write, and execute permissions to the users and groups they choose. RBAC is a type of access control that defines permissions based on a user's role. Roles are assigned to users based on their job function or responsibilities. For example, a user with the role of "employee" might have read-only access to all files, while a user with the role of "manager" might have read, write, and execute permissions to all files.
upvoted 2 times
...
SecurityGuy
3 months, 3 weeks ago
Selected Answer: A
DAC (Discretionary Access Control): Object Owner determines permissions and "provides users a certain amount of control" over their data, it is a least restrictive model. >> I would go on A on this one. B. DAC requires explicit authorization for a given user on a given object, RBAC requires specific conditions. >> The specific condition thing feels like more inclined to ABAC wherein Attributes of the subject determines permissions.
upvoted 1 times
...
mozaki
9 months ago
Selected Answer: B
b is correct
upvoted 1 times
...
trigger4848
1 year, 1 month ago
does anyone think B is correct ?
upvoted 1 times
MaliDong
1 year, 1 month ago
I would say that the 'specific conditions' makes B incorrect. user has certain role is type of 'specific condition', but 'specific conditions' can covers more than that.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago