Soru

Zorluk: KolayIdentity and Access Management Architecture

A security team is implementing an access control model that evaluates contextual variables—such as user location, device security compliance, time of request, and resource sensitivity—before granting access. Which access control architecture model natively uses these dynamic characteristics to make authorization decisions?

  1. Attribute-Based Access Control (ABAC)Cevap
  2. B
    Role-Based Access Control (RBAC)
  3. C
    Mandatory Access Control (MAC)
  4. D
    Discretionary Access Control (DAC)

Cevap

Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) evaluates specific characteristics (attributes) belonging to the user, resource, action, and environment—such as IP address, device health, time of day, and data classification—to dynamically determine access permissions.

Adım Adım Çözüm

1
Analyze the access control requirement in the scenario.
The requirement specifies making authorization decisions based on dynamic contextual factors such as location, device health, time of request, and data sensitivity.
Understanding the input parameters used for access decisions helps distinguish between static and dynamic access control models.
2
Evaluate the architectural characteristics of Attribute-Based Access Control (ABAC).
ABAC grants access rights through policies that combine subject, resource, action, and environmental attributes.
ABAC is specifically designed to support fine-grained, dynamic, and context-aware authorization policies in modern security architectures.

Anahtar Kavram

Attribute-Based Access Control (ABAC)
Tahmini Süre:45s
Bu soruyu puanla