CertKeen

CISSP · Free practice question 6 of 12

Role-based access control by job function

Ashbury Hospital has thousands of staff whose system permissions depend on their job, such as nurse, pharmacist or billing clerk, and people change jobs often. The identity manager wants permissions assigned to job functions instead of to individuals. Which model should be implemented?

  1. A.Discretionary access control
  2. B.Mandatory access control
  3. C.Identity-based access control lists on each file
  4. D.Role-based access control
Show answer and explanation

Correct answer: D. Role-based access control

Why: Role-based access control assigns permissions to roles that represent job functions and then assigns users to roles, so a job change means moving the person to a different role rather than editing many individual permissions. Discretionary access control leaves decisions to data owners, mandatory access control relies on labels and clearances, and per-file identity ACLs are exactly the individual-level management the hospital wants to avoid.

More free CISSP questions