Access Control Models Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control Models flashcards as text
In RBAC, what term describes the assignment of a role to a user that allows the user to exercise the role's permissions?
Answer: User-Role Assignment (URA)
User-Role Assignment (URA) is the relationship in RBAC that maps users to roles, granting them all permissions associated with those roles.
Which RBAC constraint ensures that a user cannot hold two conflicting roles, such as both 'payment initiator' and 'payment approver'?
Answer: Static Separation of Duty (SSD)
Static SSD prevents users from being assigned to mutually exclusive roles simultaneously in their user-role assignment, enforcing segregation of duties.
What distinguishes Dynamic Separation of Duty (DSD) from Static Separation of Duty (SSD) in RBAC?
Answer: DSD applies constraints at session activation; SSD applies at role assignment
DSD allows a user to hold conflicting roles but prevents activating them simultaneously in the same session, while SSD prevents conflicting role assignments entirely.
A healthcare system grants doctors read access to all patient records but write access only to their own patients' records. This scenario best illustrates which model?
Answer: ABAC
ABAC can combine role attributes (doctor) with relationship attributes (my patient) and action attributes (read vs. write) to enforce this nuanced policy.
The Chinese Wall Model is primarily designed to prevent:
Answer: Conflicts of interest between competing organizations
The Chinese Wall (Brewer-Nash) Model prevents consultants from accessing data from competing companies by dynamically restricting access based on prior accesses.
In MAC systems, sensitivity labels typically consist of which two components?
Answer: Classification level and categories (compartments)
MAC labels combine a hierarchical classification (e.g., Top Secret) with non-hierarchical categories or compartments (e.g., NUCLEAR, NATO) for fine-grained control.
Which access control model is considered the most flexible but also the most administratively complex due to policy rule management?
Answer: ABAC
ABAC offers the most flexibility by combining unlimited attributes into policies, but this creates significant complexity in authoring, maintaining, and debugging policies.