Which statement describes ABAC decision making?

Study for the Industrial Security Test. Use flashcards and multiple-choice questions with detailed explanations. Prepare effectively for your exam!

Multiple Choice

Which statement describes ABAC decision making?

Explanation:
ABAC decision making is attribute-driven: an access request is granted only after evaluating attributes tied to the user, the resource, the requested action, and the environment. Attributes can include who the user is (department, clearance), what is being accessed (data classification, resource type), what operation is requested (read, write), and contextual factors (time, location, network). Policies combine these attributes to decide allow or deny, enabling precise, context-aware access control that adapts to different situations. This contrasts with fixed roles, which describes RBAC where access is tied to predefined roles rather than the full set of attributes. Limiting the description to geographic location misses the breadth ABAC uses, and vendor agreements aren’t the basis for dynamic ABAC decisions.

ABAC decision making is attribute-driven: an access request is granted only after evaluating attributes tied to the user, the resource, the requested action, and the environment. Attributes can include who the user is (department, clearance), what is being accessed (data classification, resource type), what operation is requested (read, write), and contextual factors (time, location, network). Policies combine these attributes to decide allow or deny, enabling precise, context-aware access control that adapts to different situations.

This contrasts with fixed roles, which describes RBAC where access is tied to predefined roles rather than the full set of attributes. Limiting the description to geographic location misses the breadth ABAC uses, and vendor agreements aren’t the basis for dynamic ABAC decisions.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy