Which access control model uses roles to grant permissions to users?

Study for the CompTIA Cloud+ exam. Enhance your skills with flashcards and multiple choice questions, each supported by hints and explanations. Prepare effectively for your certification!

Multiple Choice

Which access control model uses roles to grant permissions to users?

Explanation:
Roles-based access control uses roles as the central mechanism for granting permissions. In this model, permissions are grouped into roles rather than assigned to individual users, and users gain access by being assigned to one or more roles. This makes administration scalable in large environments because you can manage access by modifying role memberships rather than updating permissions for each user. It also supports least privilege and separation of duties by designing roles with the appropriate set of permissions and avoiding per-user permission drift. In contrast, other models tie access to resource owners (discretionary), fixed security policies (mandatory), or attributes of the user, resource, and environment (attribute-based).

Roles-based access control uses roles as the central mechanism for granting permissions. In this model, permissions are grouped into roles rather than assigned to individual users, and users gain access by being assigned to one or more roles. This makes administration scalable in large environments because you can manage access by modifying role memberships rather than updating permissions for each user. It also supports least privilege and separation of duties by designing roles with the appropriate set of permissions and avoiding per-user permission drift. In contrast, other models tie access to resource owners (discretionary), fixed security policies (mandatory), or attributes of the user, resource, and environment (attribute-based).

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy