Which model would be most appropriate when access decisions rely on multiple attributes of the user and the resource?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Which model would be most appropriate when access decisions rely on multiple attributes of the user and the resource?

Attribute-Based Access Control evaluates a set of attributes from the user, the resource, the requested action, and the environment to decide whether access should be granted. Instead of relying on fixed roles or static permissions, ABAC uses policies that combine multiple attributes—such as the user’s identity, department, clearance level, the sensitivity of the resource, the type of operation, the time of day, and location—to make nuanced access decisions. This allows fine-grained, context-aware control that can express complex requirements and adapt as conditions change.

The other concepts address different security concerns: Privileged Access Management focuses on protecting and controlling access to highly sensitive accounts and their sessions; password policies cover rules for credential creation and strength; hardware key managers handle the management of cryptographic keys.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy