Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 157 discussion

Actual exam question from ISC's CISSP
Question #: 157
Topic #: 1
[All CISSP Questions]

An organization would like to ensure that all new users have a predefined departmental access template applied upon creation. The organization would also like additional access for users to be granted on a per-project basis. What type of user access administration is BEST suited to meet the organization's needs?

  • A. Decentralized
  • B. Hybrid
  • C. Centralized
  • D. Federated
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
RVoigt
Highly Voted 1 year, 8 months ago
Selected Answer: B
CISSP Official Student Guide pg 169 "Hybrid: In a hybrid approach, centralized control is exercised for some information and decentralized control is allowed for other information. One typical arrangement is that central administration is responsible for the broadest and most basic access, and the creators/owners of files control the types of access or users’ abilities for the files under their control. For example, when a new employee is hired into a department, a central administrator might provide the employee with access permissions based on the functional element they are assigned to, the job classification and the specific task they were hired to work on. The employee might have readonly access to an organization-wide SharePoint document library and to project status report files but read-and-write privileges to his department’s weekly activities report. Also, if the employee leaves a project, the project manager can easily close that employee’s access to that file."
upvoted 8 times
...
Oppenheimer
Highly Voted 2 years, 1 month ago
Selected Answer: B
Agree with B it is a hybrid of RBAC and ABAC
upvoted 6 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 2 times
...
...
Dtony66
Most Recent 6 months, 3 weeks ago
Selected Answer: B
How could it be D when Federated refers to inter organizational?
upvoted 1 times
...
Vasyamba1
8 months ago
Selected Answer: C
I go with C. OSG - Centralized access control implies that a single entity within a system performs all authorization verification.
upvoted 1 times
...
homeysl
8 months, 1 week ago
Selected Answer: C
Why B? Hybrid is both on-prem and cloud. I didn't see anything about cloud in the question.
upvoted 2 times
...
maawar83
11 months ago
B It Is!
upvoted 1 times
...
GPrep
11 months, 1 week ago
I believe the answer is C. Hybrid and Federated refer to the back end solution for IAM, including SSO, etc. See page 688 of the official study guide "Hybrid Environment". According to pg 659, there are two options for Identity Management, Centralized and Decentralized. Therefore, I choose C.
upvoted 2 times
...
BoZT
1 year, 2 months ago
Selected Answer: B
Combination of RBAC and ABAC, ABAC can be per project basis.
upvoted 1 times
...
Dee83
1 year, 10 months ago
B. Hybrid user access administration is BEST suited to meet the organization's needs. Hybrid user access administration is a combination of both centralized and decentralized access administration. It allows for a predefined departmental access template to be applied to new users upon creation, which is a centralized approach. And also allows for additional access to be granted on a per-project basis, which is a decentralized approach. This allows for a balance between centralized control and flexibility for departments and project teams to manage their own access needs.
upvoted 2 times
...
Ncoa
2 years, 1 month ago
Selected Answer: B
Agree with B it is a hybrid of RBAC and ABAC
upvoted 3 times
...
Cww1
2 years, 2 months ago
agree with B https://www.serverbrain.org/infrastructure-design-2003/identifying-the-hybrid-administration-model.html
upvoted 1 times
...
mrgod
2 years, 2 months ago
Selected Answer: B
The question is talking about inside organization, so this is nothing to do with Federate..I think hybrid is a better choice.
upvoted 3 times
...
stickerbush1970
2 years, 2 months ago
I would go with A
upvoted 1 times
...
Stevooo
2 years, 2 months ago
Selected Answer: D
Can someone justify this answer please
upvoted 5 times
kurtvon
2 years ago
Only: Because the test said so... (This question is a bad question)
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...