200-201 exam dumps

200-201 practice question 67 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 67

Select 3

A cybersecurity analyst is tasked with implementing Attribute-Based Access Control (ABAC) in an organization to secure access to sensitive financial records. The access policy requires that only employees in the 'Finance' department, working on a company-issued device, and physically located in the corporate office are allowed to access the records. Which attributes should the analyst configure in the ABAC system to meet this requirement?

  1. A

    Department attribute to verify if the user belongs to 'Finance'

  2. B

    Device attribute to confirm the device is company-issued

  3. C

    Time attribute to restrict access to business hours

  4. D

    Location attribute to ensure the user is in the corporate office

  5. E

    User's role to verify if they are a manager

Show answer and explanation

Correct answers: A, B, D

Explanation

Attribute-Based Access Control (ABAC) relies on attributes such as user characteristics, device properties, and environmental context to enforce access policies. In this scenario, the policy explicitly requires attributes related to the user's department (Finance), the device (company-issued), and the location (corporate office). The correct configuration of these attributes ensures that access is granted only to employees meeting all specified criteria, thereby securing sensitive financial records.

  • A. Correct.

    Correct. The department attribute ensures that only employees in the 'Finance' department can access the records, aligning with the policy requirement.

  • B. Correct.

    Correct. The device attribute is necessary to confirm that the user is using a company-issued device, as specified in the policy.

  • C. Incorrect.

    Incorrect. The policy does not mention any restriction based on the time of access, so the time attribute is not applicable.

  • D. Correct.

    Correct. The location attribute ensures that the user is physically in the corporate office, which is a requirement of the policy.

  • E. Incorrect.

    Incorrect. While roles like 'manager' may be used in other access control policies, this scenario does not specify any restrictions based on user roles.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam