200-201 exam dumps

200-201 practice question 56 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 56

Select 2

A company is implementing a mandatory access control (MAC) system to protect sensitive customer data. In this system, access policies are strictly defined and enforced by the operating system based on classifications such as 'Confidential', 'Secret', and 'Top Secret'. Which of the following scenarios accurately reflects how MAC operates in this environment?

  1. A

    A user with 'Secret' clearance can access files classified as 'Confidential' without additional permissions.

  2. B

    A user with 'Confidential' clearance cannot access files classified as 'Secret', even if explicitly granted permission by their manager.

  3. C

    Access permissions are defined and enforced by the system administrator, but users can modify their own access permissions as needed.

  4. D

    Access to resources is determined by comparing the user's clearance level with the classification of the resource.

  5. E

    Users can share access to resources with others by modifying file permissions if they are the file owners.

Show answer and explanation

Correct answers: B, D

Explanation

Mandatory Access Control (MAC) is a strict security model where access to resources is determined by predefined classifications and clearance levels. Users cannot modify permissions or share access, and policies are enforced by the system without exceptions. Options 2 and 4 accurately describe how MAC operates, making them the correct choices.

  • A. Incorrect.

    Incorrect: In a MAC system, a user's clearance level determines access, but having a higher clearance does not automatically grant access to lower-classified files without appropriate policies in place.

  • B. Correct.

    Correct: In a MAC system, strict controls are enforced by the system. Even if a manager wants to grant access, the system policies cannot be bypassed.

  • C. Incorrect.

    Incorrect: In a MAC model, users cannot modify their own access permissions; only the predefined policies enforced by the system are followed.

  • D. Correct.

    Correct: MAC compares the user's clearance level with the classification level of the resource to determine access. This is a core principle of MAC.

  • E. Incorrect.

    Incorrect: In a MAC system, users cannot share access or modify file permissions. All access is controlled by the system based on strict policies.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam