Authorization & Access Control Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Authorization & Access Control flashcards as text
Which access control model assigns permissions based on user attributes, resource attributes, and environmental conditions?
Answer: Attribute-Based Access Control (ABAC)
ABAC evaluates multiple attributes simultaneously — including subject, object, and environment attributes — to make fine-grained authorization decisions.
Under the principle of least privilege, a system administrator who performs daily backups should have which of the following?
Answer: Only the rights needed to perform backup operations
Least privilege requires granting only the minimum access necessary for a user to perform their specific job functions.
A security label of 'SECRET//NOFORN' in a MAC system indicates that the data is classified SECRET and:
Answer: Cannot be released to foreign nationals
NOFORN is a handling caveat meaning the information is not releasable to foreign nationals or foreign governments.
Which authorization concept ensures that no single individual can complete a sensitive transaction alone?
Answer: Separation of duties
Separation of duties divides critical tasks among multiple people to prevent fraud and error by requiring collusion to circumvent controls.
In RBAC, which component maps users to collections of permissions?
Answer: Role
In RBAC, roles are defined sets of permissions that are then assigned to users, centralizing permission management.
An organization implements a policy that prevents a user who approves purchase orders from also creating them. This is an example of:
Answer: Separation of duties
Separation of duties requires that conflicting roles — such as creator and approver — be assigned to different individuals.
Which of the following best describes 'role explosion' in an RBAC implementation?
Answer: An unmanageable proliferation of overly specific roles
Role explosion occurs when organizations create too many granular roles to accommodate exceptions, making the RBAC system difficult to manage.