exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 229 discussion

Actual exam question from ISC's CISSP
Question #: 229
Topic #: 1
[All CISSP Questions]

Which type of access control includes a system that allows only users that are type=managers and department=sales to access employee records?

  • A. Role-based access control (RBAC)
  • B. Attribute-based access control (ABAC)
  • C. Discretionary access control (DAC)
  • D. Mandatory access control (MAC)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 1 year, 10 months ago
Answer correct "ABAC can control access based on three different attribute types: user attributes, attributes associated with the application or system to be accessed, and current environmental conditions. An example of ABAC would be allowing only users who are type=employees and have department=HR to access the HR/Payroll system and only during business hours within the same timezone as the company." https://blog.identityautomation.com/rbac-vs-abac-access-control-models-iam-explained#:~:text=An%20example%20of%20ABAC%20would,is%20also%20the%20most%20complex.
upvoted 7 times
Highly Voted 1 year, 6 months ago
Selected Answer: B
CISSP Offical Study Guide pg 682 - "Attribute-Based Access Control A key characteristic of the Attribute-Based Access Control (ABAC) model is its use of rules that can include multiple attributes." If it was just managers then Role-Based. Once multiple properties are added it becomes Attribute-Based.
upvoted 5 times
8 months, 2 weeks ago
You are 100% correct!
upvoted 1 times
1 year, 3 months ago
B is correct
upvoted 1 times
Most Recent 1 month ago
Selected Answer: A
I think it's A. Eventhough the question mentioned two elements, both would construct a specific role, that is a sales manager.
upvoted 1 times
7 months, 2 weeks ago
Selected Answer: B
ABAC defines access control policies based on attributes associated with users, resources, and the environment. In this case, the attributes "type" and "department" are used to determine access privileges.
upvoted 1 times
8 months, 2 weeks ago
B. Attribute-based access control (ABAC) Attribute-based access control (ABAC) uses various attributes and policies to make access control decisions, taking into account specific attributes associated with users, resources, and other factors to determine whether access should be granted or denied. In this scenario, the attributes "type" and "department" are used to control access to employee records based on the user's role and department.
upvoted 1 times
8 months, 3 weeks ago
Selected Answer: A
Opinions differ between A and B, but I believe it's A. The problem statement only mentions the role of Sales Manager. To choose B, I feel there should be additional conditions specified in the problem statement. I would confidently choose B if there were additional conditions like: Access allowed only from 10 am to 5 pm. No access on weekends.
upvoted 1 times
8 months, 3 weeks ago
ABAC 100%
upvoted 1 times
10 months, 1 week ago
Selected Answer: B
B. Those are user attributes
upvoted 1 times
11 months ago
Selected Answer: B
Attribute-based access control (ABAC) is a type of access control that uses attributes, such as user roles, department, and location, to determine whether a user has access to a particular resource. In the scenario you provided, the access control system is using attributes such as the user's role (manager) and department (sales) to determine whether they should be granted access to employee records. Therefore, ABAC is the most appropriate type of access control in this scenario.
upvoted 2 times
1 year, 2 months ago
Selected Answer: A
The role is sales manager, so RBAC.
upvoted 4 times
1 year, 7 months ago
(Option B) Attribute-based access control (ABAC) includes a system that allows only users that are type=managers and department=sales to access employee records.
upvoted 1 times
1 year, 7 months ago
Selected Answer: B
The correct answer is B. Attribute-based access control (ABAC) allows users to access resources based on their attributes, such as their type (e.g. manager) and department (e.g. sales). This type of access control allows for more fine-grained control over access to resources than other types of access control, such as role-based access control (RBAC) or discretionary access control (DAC).
upvoted 1 times
1 year, 8 months ago
Selected Answer: B
Correct answer B
upvoted 1 times
1 year, 8 months ago
Selected Answer: A
Vote A, type=managers and department=sales is about the RBAC
upvoted 3 times
1 year, 9 months ago
Selected Answer: B
ABAC is a control access based attribute types
upvoted 1 times
1 year, 10 months ago
Selected Answer: B
This is granting them access to employee records by combining two specific attributes so "B" is the correct answer.
upvoted 4 times
1 year, 11 months ago
Selected Answer: B
These are attributes
upvoted 4 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago