Soru

Zorluk: OrtaAuthentication, Authorization, and Accounting (AAA)

A cloud security administrator is updating the identity and access management framework for an enterprise application platform to align strictly with the AAA model. Which of the following implementation steps specifically address the Authorization pillar of AAA? (Select TWO.)

  1. Applying Role-Based Access Control (RBAC) policies to assign specific resource permissions based on job functionCevap
  2. B
    Verifying user credentials and time-based one-time password (TOTP) codes through a central identity provider
  3. Enforcing Attribute-Based Access Control (ABAC) rules to evaluate environmental context and resource tags before granting request accessCevap
  4. D
    Configuring centralized event logging to record all user session API calls to an append-only audit bucket

Cevap

The configurations that specifically address Authorization are applying Role-Based Access Control (RBAC) policies to assign resource permissions and enforcing Attribute-Based Access Control (ABAC) rules based on context and resource tags.
Authorization determines the permissions and access rights granted to an identity after it has been authenticated. Both Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) are access control frameworks designed specifically to define and enforce what actions users or services can perform on target resources.

Adım Adım Çözüm

1
Differentiate between the three pillars of the AAA model: Authentication (verifying identity), Authorization (determining permissions and access rights), and Accounting (tracking activity and keeping logs).
Established that the question requires identifying access control mechanisms that enforce permissions.
Authorization explicitly governs what actions an authenticated identity is allowed to execute.
2
Evaluate each configuration option against the Authorization definition.
RBAC and ABAC govern permissions and access rights (Authorization). Credential and TOTP verification establishes identity (Authentication). Activity logging tracks historical user actions (Accounting).
Correctly categorizes each control mechanism to isolate the two valid Authorization mechanisms.

Anahtar Kavram

Authentication, Authorization, and Accounting (AAA)
Bu soruyu puanla