ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team is designing an API for an electronic health record system hosted in a cloud environment. All users authenticate via SAML SSO. The security policy states that any licensed physician may read any patient record, but only the record's attending physician may modify it. Which authorization model best satisfies this requirement at the API layer?
Attribute-Based Access Control (ABAC) policies evaluated by the API gateway
Discretionary Access Control (DAC) allowing physicians to maintain access control lists on their patients' records
Role-Based Access Control (RBAC) with static physician and nurse roles
Mandatory Access Control (MAC) that labels each patient record with a fixed sensitivity level
Attribute-Based Access Control evaluates attributes about the subject (e.g., role=physician, userID), the object (e.g., attendingPhysicianID on the record), and the requested action (read or write). A policy can therefore permit read access to all users whose role attribute equals physician while restricting write access to those whose userID matches the record's attendingPhysicianID. Traditional role-based access control cannot easily express this per-record condition without creating an explosion of roles, discretionary access control would rely on individual users to manage ACLs, and mandatory access control uses fixed classification labels that do not reflect dynamic doctor-patient assignments. Hence, ABAC is the most appropriate choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Attribute-Based Access Control (ABAC)?
Open an interactive chat with Bash
How does SAML SSO integrate with ABAC in API designs?
Open an interactive chat with Bash
Why is ABAC better than RBAC for this healthcare scenario?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .