Giving a coworker access permissions by the resource owner without central policy control describes which model?

Study for the CompTIA Cloud+ exam. Enhance your skills with flashcards and multiple choice questions, each supported by hints and explanations. Prepare effectively for your certification!

Multiple Choice

Giving a coworker access permissions by the resource owner without central policy control describes which model?

Explanation:
Discretionary Access Control is at work here: the resource owner decides who can access it and what they can do with it. In DAC, permissions are granted at the owner's discretion, often via an access control list on the resource or by sharing a capability token. Because there isn’t a centralized policy controlling access, a coworker can be given access directly by the owner, which matches the scenario described. By contrast, Mandatory Access Control relies on system-wide, central rules and labeling; Role-Based Access Control assigns permissions based on a user’s role; and Attribute-Based Access Control uses attributes and policies to determine access.

Discretionary Access Control is at work here: the resource owner decides who can access it and what they can do with it. In DAC, permissions are granted at the owner's discretion, often via an access control list on the resource or by sharing a capability token. Because there isn’t a centralized policy controlling access, a coworker can be given access directly by the owner, which matches the scenario described.

By contrast, Mandatory Access Control relies on system-wide, central rules and labeling; Role-Based Access Control assigns permissions based on a user’s role; and Attribute-Based Access Control uses attributes and policies to determine access.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy