← All CAP Flashcard Decks

Authorization & Access Control Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Authorization & Access Control flashcards as text
  1. Which access control model assigns permissions based on user attributes, resource attributes, and environmental conditions?

    Answer: Attribute-Based Access Control (ABAC)

    ABAC evaluates multiple attributes simultaneously — including subject, object, and environment attributes — to make fine-grained authorization decisions.

  2. Under the principle of least privilege, a system administrator who performs daily backups should have which of the following?

    Answer: Only the rights needed to perform backup operations

    Least privilege requires granting only the minimum access necessary for a user to perform their specific job functions.

  3. A security label of 'SECRET//NOFORN' in a MAC system indicates that the data is classified SECRET and:

    Answer: Cannot be released to foreign nationals

    NOFORN is a handling caveat meaning the information is not releasable to foreign nationals or foreign governments.

  4. Which authorization concept ensures that no single individual can complete a sensitive transaction alone?

    Answer: Separation of duties

    Separation of duties divides critical tasks among multiple people to prevent fraud and error by requiring collusion to circumvent controls.

  5. In RBAC, which component maps users to collections of permissions?

    Answer: Role

    In RBAC, roles are defined sets of permissions that are then assigned to users, centralizing permission management.

  6. An organization implements a policy that prevents a user who approves purchase orders from also creating them. This is an example of:

    Answer: Separation of duties

    Separation of duties requires that conflicting roles — such as creator and approver — be assigned to different individuals.

  7. Which of the following best describes 'role explosion' in an RBAC implementation?

    Answer: An unmanageable proliferation of overly specific roles

    Role explosion occurs when organizations create too many granular roles to accommodate exceptions, making the RBAC system difficult to manage.