CISSP Offical Study Guide pg 682 - "Attribute-Based Access Control A key characteristic of the Attribute-Based Access Control (ABAC) model is its use of rules that can include multiple attributes."
If it was just managers then Role-Based. Once multiple properties are added it becomes Attribute-Based.
Answer correct
"ABAC can control access based on three different attribute types: user attributes, attributes associated with the application or system to be accessed, and current environmental conditions.
An example of ABAC would be allowing only users who are type=employees and have department=HR to access the HR/Payroll system and only during business hours within the same timezone as the company."
https://blog.identityautomation.com/rbac-vs-abac-access-control-models-iam-explained#:~:text=An%20example%20of%20ABAC%20would,is%20also%20the%20most%20complex.
In ABAC, access decisions are based on attributes of: 1. the user (e.g., type=manager), 2. the resource (e.g., record_type=employee), 3 the environment (e.g., time of access, location)
ABAC defines access control policies based on attributes associated with users, resources, and the environment. In this case, the attributes "type" and "department" are used to determine access privileges.
B. Attribute-based access control (ABAC)
Attribute-based access control (ABAC) uses various attributes and policies to make access control decisions, taking into account specific attributes associated with users, resources, and other factors to determine whether access should be granted or denied. In this scenario, the attributes "type" and "department" are used to control access to employee records based on the user's role and department.
Opinions differ between A and B, but I believe it's A. The problem statement only mentions the role of Sales Manager.
To choose B, I feel there should be additional conditions specified in the problem statement. I would confidently choose B if there were additional conditions like:
Access allowed only from 10 am to 5 pm.
No access on weekends.
Attribute-based access control (ABAC) is a type of access control that uses attributes, such as user roles, department, and location, to determine whether a user has access to a particular resource. In the scenario you provided, the access control system is using attributes such as the user's role (manager) and department (sales) to determine whether they should be granted access to employee records. Therefore, ABAC is the most appropriate type of access control in this scenario.
(Option B)
Attribute-based access control (ABAC) includes a system that allows only users that are type=managers and department=sales to access employee records.
The correct answer is B. Attribute-based access control (ABAC) allows users to access resources based on their attributes, such as their type (e.g. manager) and department (e.g. sales). This type of access control allows for more fine-grained control over access to resources than other types of access control, such as role-based access control (RBAC) or discretionary access control (DAC).
This section is not available anymore. Please use the main Exam Page.CISSP Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
RVoigt
Highly Voted 1 year, 7 months agoSoleandheel
9 months, 4 weeks agojackdryan
1 year, 4 months agoJAckThePip
Highly Voted 2 years agoBigITGuy
Most Recent 1 week, 2 days agoKakekGuru
2 months, 2 weeks ago629f731
9 months agoSoleandheel
9 months, 4 weeks ago[Removed]
10 months, 1 week agoshmoeee
10 months, 1 week agohomeysl
11 months, 3 weeks ago74gjd_37
1 year agopete79
1 year, 4 months agoDee83
1 year, 8 months agoDJOEK
1 year, 9 months agorajkamal0
1 year, 9 months agoIvanchun
1 year, 9 months agoIXone
1 year, 11 months agoWiDeBarulho
1 year, 11 months ago