exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 493 discussion

Actual exam question from CompTIA's CAS-004
Question #: 493
Topic #: 1
[All CAS-004 Questions]

A commercial OSINT provider utilizes and reviews data from various sources of publicly available information. The provider is transitioning the subscription service to a model that limit's the scope of available data based on subscription tier. Which of the following approaches would best ensure subscribers are only granted access to data associated with their tier? (Choose two.)

  • A. Storing collected data on separate physical media per tier
  • B. Controlling access to data based on the role of users
  • C. Employing attribute-based access control
  • D. Implementing a behavior-based IDS positioned at the storage network gateway
  • E. Establishing a classification and labeling scheme
  • F. Implementing a mandatory access control scheme
Show Suggested Answer Hide Answer
Suggested Answer: BE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
3 weeks, 2 days ago
Selected Answer: BC
B. Controlling access to data based on the role of users: This approach involves Role-Based Access Control (RBAC), where access is granted based on the user’s role. In this case, the user’s subscription tier would be tied to their role, which can limit the data they are allowed to access. For example, if a user is subscribed to a basic tier, they will only be able to access data available to that tier. This is a straightforward and effective way to ensure that only authorized users can access the data that is specific to their subscription level. C. Employing attribute-based access control: Attribute-Based Access Control (ABAC) involves granting access based on specific attributes, such as user characteristics (e.g., subscription tier) and the attributes of the data (e.g., the data's classification or level of access). This allows for more fine-grained control compared to RBAC, as it can evaluate both the user's attributes (tier, subscription type, etc.) and the data’s attributes (data sensitivity, type, or tier) to make access decisions.
upvoted 1 times
...
Bright07
3 months, 2 weeks ago
To ensure subscribers are only granted access to data associated with their subscription tier, the best approaches would be: B. Controlling access to data based on the role of users. C. Employing attribute-based access control. Both approaches focus on managing access based on defined roles or attributes, ensuring that users can only access data relevant to their specific subscription level. This helps in maintaining data segregation according to subscription tiers effectively.
upvoted 2 times
...
snowmaggedon
4 months, 2 weeks ago
Another confusing Comptia question. Are they asking for 2 different approached or two different options, when combined, give the right approach? BE seems correct but talking through it with ChatGPT, it assumes that the question wants 2 separate approaches- BC
upvoted 2 times
...
Cottoncandylalala
5 months, 1 week ago
Why not C?
upvoted 1 times
...
armid
6 months, 1 week ago
Selected Answer: BE
should be BE
upvoted 3 times
...
isaphiltrick
6 months, 1 week ago
Selected Answer: BE
Based on the requirement to ensure subscribers are only granted access to data associated with their subscription tier, the two best approaches would be: • B. Controlling access to data based on the role of users. This approach involves defining access permissions based on the roles or subscriptions of users. Each tier of subscription would correspond to a specific role or access level, ensuring that users can only access data appropriate for their subscription tier. • E. Establishing a classification and labeling scheme. By implementing a classification and labeling scheme, the data can be categorized based on sensitivity or subscription tier. Access controls can then be applied based on these classifications, ensuring that subscribers can only access data that corresponds to their subscription level.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago