200-201 exam dumps

200-201 practice question 55 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 55

Single answer

A healthcare organization uses a database to store sensitive patient records. The organization implements a security model where users can only access data based on their assigned roles, clearance levels, and the classification of the data itself. A database administrator attempts to access a record classified as 'Top Secret,' but they are denied access despite having administrative privileges. Which access control model is being enforced in this scenario?

  1. A

    Mandatory Access Control (MAC)

  2. B

    Discretionary Access Control (DAC)

  3. C

    Role-Based Access Control (RBAC)

  4. D

    Attribute-Based Access Control (ABAC)

Show answer and explanation

Correct answer: A

Explanation

The scenario describes a strict enforcement model where access to sensitive data is determined by security classifications and clearance levels. This aligns with the Mandatory Access Control (MAC) model, which is designed to prevent unauthorized access even for high-level users like administrators. Unlike DAC, RBAC, or ABAC, MAC relies on predefined system rules that cannot be bypassed by users.

  • A. Correct.

    Mandatory Access Control (MAC) enforces strict policies where access is based on predefined permissions determined by the system, not the user. The denial of access for the administrator aligns with MAC because even high-level users cannot override classification rules.

  • B. Incorrect.

    Discretionary Access Control (DAC) allows data owners to determine who can access their data. In this scenario, access decisions are not left to individual discretion but are enforced at a higher system level, making DAC incorrect.

  • C. Incorrect.

    Role-Based Access Control (RBAC) assigns permissions based on user roles. Although roles are important, this scenario involves access restrictions based on security classifications, which are characteristic of MAC, not RBAC.

  • D. Incorrect.

    Attribute-Based Access Control (ABAC) uses policies based on attributes such as user characteristics and environmental conditions. While ABAC is flexible, the strict enforcement of classification levels in the scenario points to MAC, not ABAC.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam