Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 3 discussion

Actual exam question from ISC's CISSP
Question #: 3
Topic #: 1
[All CISSP Questions]

An organization would like to implement an authorization mechanism that would simplify the assignment of various system access permissions for many users with similar job responsibilities. Which type of authorization mechanism would be the BEST choice for the organization to implement?

  • A. Role-based access control (RBAC)
  • B. Discretionary access control (DAC)
  • C. Content-dependent Access Control
  • D. Rule-based Access Control
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Jfrei
Highly Voted 2 years, 2 months ago
Selected Answer: A
A. Users with similar responsibilities should always be assigned a role. This simplifies the process of granting access when users join the team as well as move to new teams.
upvoted 37 times
jackdryan
1 year, 7 months ago
A is correct
upvoted 1 times
...
...
AZSID
Most Recent 8 months, 3 weeks ago
Selected Answer: A
A is Correct
upvoted 1 times
...
SKainth
9 months, 2 weeks ago
Selected Answer: A
Question is talking about Access Permissions with Similar Job Roles. I will go with answer A.
upvoted 1 times
...
AttahNet
1 year, 2 months ago
Policy neutral access control mechanism defined around roles and privileges. So A Is the answer.
upvoted 2 times
...
wingcheuk
1 year, 5 months ago
Selected Answer: A
I will pick A for answer. In domain 5, it says: RBAC is where access to objects is granted based on the role of the subject. DAC gives subjects full control of objects they have created or been given access to. Content-Based Access Control is granted bases on the attributes or content of an object. Rule Based Access Control is access that’s granted based on IF/THEN statements. As the question is asking an authorization mechanism for many user with similar job responsibilities (role). Only RBAC uses role for authorization, so it is the best option.
upvoted 1 times
...
wanne
1 year, 6 months ago
Anyone seen RBAC implemented for a lots of users? I would know what I should answer. Reality is a little B with a lot of D, since B is easier to implement and D easier to understand.
upvoted 1 times
...
jackdryan
1 year, 7 months ago
A is correct.
upvoted 1 times
...
user009
1 year, 8 months ago
The correct answer is A. Explanation: The BEST choice for the organization to implement to simplify the assignment of various system access permissions for many users with similar job responsibilities would be Role-based access control (RBAC). RBAC is a widely used authorization mechanism that assigns permissions to users based on their job functions or roles. This simplifies the administration of access control by grouping users based on their job responsibilities, and granting access permissions based on those groups or roles.
upvoted 1 times
...
Overizzy
2 years ago
Selected Answer: A
A RoleBAC
upvoted 1 times
...
Eltooth
2 years, 1 month ago
Selected Answer: A
A is correct answer. RBAC
upvoted 2 times
...
franbarpro
2 years, 2 months ago
Selected Answer: A
"A" sounds good to me
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...