A company's document management system is set to only allow access to financial reports after regular business hours to users within the finance department who have a managerial role. What type of access control does this scenario exemplify?
The scenario exemplifies Rule-based access control because access is granted based on specific rules set by the system (e.g., being part of the finance department, having a managerial role, and it being outside regular business hours). In contrast, Role-based access control would grant permissions based on the role alone without considering additional factors like time. Mandatory and Discretionary access controls are not based on predefined rules tied to attributes like time or departmental role.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the key characteristics of Rule-based access control?
Open an interactive chat with Bash
How does Role-based access control differ from Rule-based access control?
Open an interactive chat with Bash
What are the four main types of access control models?