Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 229 discussion

Actual exam question from ISC's CISSP
Question #: 229
Topic #: 1
[All CISSP Questions]

Which type of access control includes a system that allows only users that are type=managers and department=sales to access employee records?

  • A. Role-based access control (RBAC)
  • B. Attribute-based access control (ABAC)
  • C. Discretionary access control (DAC)
  • D. Mandatory access control (MAC)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
JAckThePip
Highly Voted 2 years, 1 month ago
Answer correct "ABAC can control access based on three different attribute types: user attributes, attributes associated with the application or system to be accessed, and current environmental conditions. An example of ABAC would be allowing only users who are type=employees and have department=HR to access the HR/Payroll system and only during business hours within the same timezone as the company." https://blog.identityautomation.com/rbac-vs-abac-access-control-models-iam-explained#:~:text=An%20example%20of%20ABAC%20would,is%20also%20the%20most%20complex.
upvoted 7 times
...
RVoigt
Highly Voted 1 year, 9 months ago
Selected Answer: B
CISSP Offical Study Guide pg 682 - "Attribute-Based Access Control A key characteristic of the Attribute-Based Access Control (ABAC) model is its use of rules that can include multiple attributes." If it was just managers then Role-Based. Once multiple properties are added it becomes Attribute-Based.
upvoted 5 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
You are 100% correct!
upvoted 1 times
...
...
629f731
Most Recent 10 months, 2 weeks ago
Selected Answer: B
ABAC defines access control policies based on attributes associated with users, resources, and the environment. In this case, the attributes "type" and "department" are used to determine access privileges.
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
B. Attribute-based access control (ABAC) Attribute-based access control (ABAC) uses various attributes and policies to make access control decisions, taking into account specific attributes associated with users, resources, and other factors to determine whether access should be granted or denied. In this scenario, the attributes "type" and "department" are used to control access to employee records based on the user's role and department.
upvoted 1 times
...
[Removed]
11 months, 4 weeks ago
Selected Answer: A
Opinions differ between A and B, but I believe it's A. The problem statement only mentions the role of Sales Manager. To choose B, I feel there should be additional conditions specified in the problem statement. I would confidently choose B if there were additional conditions like: Access allowed only from 10 am to 5 pm. No access on weekends.
upvoted 1 times
...
shmoeee
12 months ago
ABAC 100%
upvoted 1 times
...
homeysl
1 year, 1 month ago
Selected Answer: B
B. Those are user attributes
upvoted 1 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: B
Attribute-based access control (ABAC) is a type of access control that uses attributes, such as user roles, department, and location, to determine whether a user has access to a particular resource. In the scenario you provided, the access control system is using attributes such as the user's role (manager) and department (sales) to determine whether they should be granted access to employee records. Therefore, ABAC is the most appropriate type of access control in this scenario.
upvoted 2 times
...
pete79
1 year, 6 months ago
Selected Answer: A
The role is sales manager, so RBAC.
upvoted 4 times
...
Dee83
1 year, 10 months ago
(Option B) Attribute-based access control (ABAC) includes a system that allows only users that are type=managers and department=sales to access employee records.
upvoted 1 times
...
DJOEK
1 year, 10 months ago
Selected Answer: B
The correct answer is B. Attribute-based access control (ABAC) allows users to access resources based on their attributes, such as their type (e.g. manager) and department (e.g. sales). This type of access control allows for more fine-grained control over access to resources than other types of access control, such as role-based access control (RBAC) or discretionary access control (DAC).
upvoted 1 times
...
rajkamal0
1 year, 11 months ago
Selected Answer: B
Correct answer B
upvoted 1 times
...
Ivanchun
1 year, 11 months ago
Selected Answer: A
Vote A, type=managers and department=sales is about the RBAC
upvoted 3 times
...
IXone
2 years ago
Selected Answer: B
ABAC is a control access based attribute types
upvoted 1 times
...
WiDeBarulho
2 years, 1 month ago
Selected Answer: B
This is granting them access to employee records by combining two specific attributes so "B" is the correct answer.
upvoted 4 times
...
John129087
2 years, 2 months ago
Selected Answer: B
These are attributes
upvoted 4 times
...
matt1976
2 years, 2 months ago
I say A. An example of ABAC would be allowing only users who are type=employees and have department=HR to access the HR/Payroll system and only during business hours within the same timezone as the company.
upvoted 4 times
jaysparky
2 years, 1 month ago
I think you meant B
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...