Access Control Models Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control Models flashcards as text
Which access control model concept requires that a transaction be completed entirely or not at all, supporting data integrity?
Answer: Clark-Wilson Integrity Model atomicity requirement
Clark-Wilson enforces well-formed transactions that are atomic, consistent, isolated, and durable (ACID properties), ensuring data integrity is maintained.
A company implements access control where a manager can temporarily grant their permissions to a delegate while on leave. This is an example of:
Answer: Permission delegation
Permission delegation allows an authorized user to temporarily transfer a subset of their permissions to another user, common in workflow and identity governance systems.
In the context of IAM governance, a Segregation of Duties (SoD) violation occurs when:
Answer: A user holds access rights that span the full lifecycle of a critical transaction
SoD violations exist when one person can initiate, approve, and complete a sensitive transaction without any checks, enabling fraud or error without detection.
Which NIST RBAC model level adds role hierarchies to the flat RBAC model?
Answer: Hierarchical RBAC
Hierarchical RBAC (NIST Level 2) adds senior/junior role relationships where senior roles inherit all permissions of junior roles, enabling permission reuse.
When implementing ABAC, a policy stating 'Allow access if user.clearance >= resource.classification AND user.department == resource.owner_department' is an example of:
Answer: An ABAC policy rule combining subject and resource attributes
This is a classic ABAC policy rule that combines subject attributes (clearance, department) with resource attributes (classification, owner department) to make an access decision.
In an OAuth 2.0 authorization framework, which component represents the access control decision enforcer that validates tokens before granting resource access?
Answer: Resource Server
The Resource Server validates the OAuth access token and enforces the scopes and permissions granted by the Authorization Server before serving protected resources.
Which access control model would BEST address the need to prevent a financial analyst from accessing client data from two competing firms they advise?
Answer: Chinese Wall (Brewer-Nash) Model
The Chinese Wall Model dynamically restricts access based on previous access history, preventing access to competing organizations' data to avoid conflicts of interest.