โ† All CIAM Flashcard Decks

Access Control Models Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control Models flashcards as text
  1. Which access control model uses security labels and clearance levels to enforce a 'no read up, no write down' policy?

    Answer: Bell-LaPadula Model

    Bell-LaPadula enforces confidentiality by preventing subjects from reading data at higher classifications (no read up) and writing to lower classifications (no write down).

  2. In the Biba Integrity Model, the 'no write up' property means that a subject:

    Answer: Cannot write to objects at a higher integrity level

    In Biba, subjects cannot write to objects at higher integrity levels to prevent corrupting trusted data with less-trusted data.

  3. Which property of the Clark-Wilson model requires that all data modifications be performed by authorized programs called Transformation Procedures (TPs)?

    Answer: Enforcement Rule 2 (E2)

    E2 in Clark-Wilson requires that only certified TPs may manipulate Constrained Data Items (CDIs), ensuring integrity through controlled transformation.

  4. An organization needs fine-grained access control based on user department, time of day, and resource sensitivity. Which model best fits this requirement?

    Answer: Attribute-Based Access Control (ABAC)

    ABAC evaluates multiple attributes (user, environment, resource) simultaneously, making it ideal for complex, fine-grained policy requirements.

  5. In a DAC system, who ultimately controls access to a resource?

    Answer: The resource owner

    In DAC, the owner of a resource has discretion to grant or revoke access to other users, unlike MAC where the system enforces access centrally.

  6. Which access control model is most commonly used in operating systems like Windows NTFS through Access Control Lists (ACLs)?

    Answer: Discretionary Access Control (DAC)

    NTFS ACLs implement DAC by allowing resource owners and administrators to assign permissions to individual users and groups.

  7. The principle that a subject should only access resources necessary for their assigned tasks is called:

    Answer: Least Privilege

    Least Privilege restricts subjects to only the minimum access rights required to perform their job functions, reducing the attack surface.