Access Control Models Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control Models flashcards as text
Which access control model would be MOST appropriate for a government system that must enforce strict information classification and cannot allow users to override access decisions?
Answer: Mandatory Access Control
MAC is mandated by the system, not individual owners, making it ideal for environments where classification policy must be enforced uniformly and cannot be overridden.
A Zero Trust Architecture primarily challenges which traditional access control assumption?
Answer: Resources inside the network perimeter are trusted by default
Zero Trust eliminates implicit trust for internal network traffic, requiring explicit verification of every access request regardless of network location.
In XACML (eXtensible Access Control Markup Language), what component makes the actual access decision?
Answer: Policy Decision Point (PDP)
The PDP evaluates applicable policies against the access request and returns Permit, Deny, NotApplicable, or Indeterminate decisions.
Role explosion is a common problem in RBAC implementations. Which approach best mitigates this issue?
Answer: Introducing role hierarchies and parameterized roles
Role hierarchies allow permission inheritance and reduce redundancy, while parameterized roles use context variables to handle variations without creating new roles.
Which access control implementation correctly prevents the 'confused deputy problem'?
Answer: Using capability tokens tied to the requesting principal's identity
Capability tokens bound to the requesting principal's identity ensure that a privileged service acts on behalf of the caller's permissions, not its own elevated permissions.
In an identity federation context, which access control mechanism allows an identity provider to communicate a user's group memberships to a service provider?
Answer: SAML attribute assertions
SAML attribute assertions can carry group membership, roles, and other attributes from the IdP to the SP, enabling the SP to make authorization decisions.
Which characteristic distinguishes Rule-Based Access Control from Role-Based Access Control (RBAC)?
Answer: Rule-Based uses system-wide condition rules; RBAC assigns permissions to job roles
Rule-Based Access Control enforces access based on system-defined conditions (time, IP, day), while RBAC grants access based on a user's assigned role in the organization.