A user requests permission to edit a specific file. What does authorization determine?
6 Access Control Online Quiz Questions
Use this free practice quiz with 20 questions to review 6 Access Control, test your knowledge, and prepare for your next test or exam.
In discretionary access control, a resource owner can grant or revoke access to that resource.
- A
True
- B
False
A company assigns permissions to job-function roles, then gives employees access through their assigned roles. Which access-control model is this? Enter the model's acronym.
A system grants access only when an applicable policy explicitly allows it. This practice is called .
A government system assigns security labels to information and applies a central policy that users cannot override by changing file permissions. Which model best fits?
- A
The resource owner decides who can access it
- B
Permissions are assigned through job-function roles
- C
A central policy uses classifications or labels to govern access
- D
Access is decided only by the user's current location
Which two practices apply the principle of least privilege? Select all that apply.
- A
Give a staff member access only to the specific records needed for assigned work
- B
Give every staff member administrator rights to avoid access delays
- C
Provide temporary, task-specific elevation for an approved exceptional task
- D
Keep all elevated permissions permanently after the task is complete
If a user was authorized when signing in, an application does not need to check authorization again when the user requests access to an individual record.
- A
True
- B
False
One employee prepares a payment and another approves it, so one person cannot complete the sensitive process alone. This illustrates .
A service account needs to process orders but not change system settings. What principle supports granting it only the access needed for that task? Enter the principle's name.
A clinic permits a clinician to view a patient's record only if the clinician is assigned to that patient and is using an approved device. Which model best expresses this context-sensitive rule?
- A
DAC, because resource owners always decide access based on device type
- B
ABAC, because the policy can evaluate subject, resource, action, and environmental attributes
- C
MAC, because the clinician can change the central policy
- D
RBAC, because role assignment necessarily checks the device being used
Which actions are part of sound access-control administration? Select all that apply.
- A
Identify protected resources, permitted actions, and approval requirements when defining policy
- B
Verify business need and obtain appropriate approval before assigning access
- C
Grant broad administrator rights first and determine business need later
- D
Keep records of access approvals and permission changes
An organization uses job roles to grant routine permissions but wants to restrict access to sensitive data based on a request's context. Explain how it could combine two access-control models to achieve this.
An administrator needs a record of which entities may access a particular file and whether each may read or edit it. What does an access-control list provide?
- A
It records which entities may access a resource and which access modes they have
- B
It assigns every user the same permissions across all resources
- C
It records only whether a user has signed in successfully
- D
It replaces the need to specify permissions for individual resources
A project-file owner decides which colleagues may read or edit the file and can revoke that access later. Which access-control model best describes this arrangement?
- A
Discretionary access control (DAC)
- B
Mandatory access control (MAC)
- C
Role-based access control (RBAC)
- D
Attribute-based access control (ABAC)
An organization assigns classifications to information and enforces a central policy that users cannot override by changing file permissions. Which access-control model is being used?
- A
Discretionary access control (DAC)
- B
Mandatory access control (MAC)
- C
Role-based access control (RBAC)
- D
Attribute-based access control (ABAC)
A company assigns invoice-approval permissions to the “finance approver” role, then gives employees access by assigning them that role. Which model does this illustrate?
- A
Discretionary access control (DAC)
- B
Mandatory access control (MAC)
- C
Role-based access control (RBAC)
- D
Attribute-based access control (ABAC)
A system permits a clinician to view a patient record only when the clinician is assigned to that patient and is using an approved device. Which access-control model most directly expresses this rule?
- A
Discretionary access control (DAC)
- B
Mandatory access control (MAC)
- C
Role-based access control (RBAC)
- D
Attribute-based access control (ABAC)
The principle of least privilege applies to service accounts and applications as well as ordinary users.
- A
True
- B
False
What is the name for a record that lists which entities may access a resource and which access modes they have?
What term describes unnecessary access accumulating over time when permissions are not adjusted as a person's duties change?