ISC2 CISSP Practice Question

A financial services firm is launching a web-based loan-processing platform that stores personally identifiable information (PII) and credit histories. The security architect must ensure employees only access data required for their responsibilities while keeping administration simple for 600 staff across underwriting, customer service, and IT support. Which access-control approach BEST meets these goals?

  • Apply mandatory access control (MAC) using hierarchical security labels for all loan records.

  • Enable single sign-on (SSO) and let application owners manually assign individual permissions to each user.

  • Deploy attribute-based access control (ABAC) that permits access solely based on IP address and time of day.

  • Implement RBAC with distinct roles for underwriting, customer service, and IT support, granting least-privilege permissions.

ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot