A financial services firm is launching a web-based loan-processing platform that stores personally identifiable information (PII) and credit histories. The security architect must ensure employees only access data required for their responsibilities while keeping administration simple for 600 staff across underwriting, customer service, and IT support. Which access-control approach BEST meets these goals?
Apply mandatory access control (MAC) using hierarchical security labels for all loan records.
Enable single sign-on (SSO) and let application owners manually assign individual permissions to each user.
Deploy attribute-based access control (ABAC) that permits access solely based on IP address and time of day.
Implement RBAC with distinct roles for underwriting, customer service, and IT support, granting least-privilege permissions.
Role-based access control (RBAC) aligns permissions with predefined job functions such as underwriter, CSR, and system administrator. This enforces least-privilege access, reduces the chance of unauthorized data exposure, and simplifies administration because rights are managed at the role level rather than per user. Mandatory access control would add unnecessary complexity for a commercial application; ABAC limited to IP and time does not adequately consider job duties; and relying on SSO with manual per-user assignments is error-prone and difficult to scale.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle behind assigning user permissions based on job functions?
Open an interactive chat with Bash
How does unauthorized access pose a risk to sensitive data?
Open an interactive chat with Bash
Why is it a bad idea to allow password sharing for convenience?
Open an interactive chat with Bash
ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .