SY0-701 exam dumps

SY0-701 practice question 359 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 359

Single answerAccess controls: Mandatory , Discretionary , Role-based , Rule-based , Attribute-based , Time-of-day restrictions , Least privilege

A hospital is deploying a new electronic health record (EHR) system. Nurses should be able to view and update patient charts only during their scheduled shifts, physicians should have broader access based on their job function, and temporary contractors should be limited to only the records for patients assigned to their department. The security team also wants to prevent individual users from granting access to others. Which access control model BEST meets these requirements while supporting least privilege?

  1. A

    Discretionary access control (DAC) with users managing file permissions for their own patient records

  2. B

    Role-based access control (RBAC) combined with rule-based restrictions for shift hours and attribute-based policies for department-assigned contractors

  3. C

    Mandatory access control (MAC) with security labels assigned only by data owners for each patient record

  4. D

    Rule-based access control only, using time-of-day rules for all users regardless of role or department

Show answer and explanation

Correct answer: B

Explanation

The best answer is RBAC combined with rule-based and attribute-based controls. In real-world environments, especially healthcare, access decisions are often layered. RBAC handles permissions by job function, which is ideal for groups such as nurses and physicians. Rule-based controls are appropriate for enforcing shift-based or time-of-day restrictions. ABAC is well suited for fine-grained decisions involving attributes like department, employment type, or patient assignment. Together, these models support the principle of least privilege by limiting access based on business need, context, and identity characteristics. DAC is inappropriate because it allows users or owners to share access, which weakens centralized governance. MAC is centralized and restrictive, but it is generally designed for classification-driven environments rather than operational healthcare workflows. These distinctions align with common Security+ guidance on access control models and with NIST best practices such as least privilege and centralized authorization found in NIST SP 800-53 and NIST SP 800-162 on ABAC.

  • A. Incorrect.

    Incorrect. DAC allows resource owners or users to grant permissions to others, which directly conflicts with the requirement to prevent individual users from granting access. While DAC can be flexible, it is generally less appropriate in regulated healthcare environments where centralized control and least privilege are priorities. Someone might choose this because it seems easy to implement at the file or record level, but it creates excessive delegation risk.

  • B. Correct.

    Correct. RBAC is the best fit for assigning baseline permissions according to job function, such as nurses versus physicians. Rule-based restrictions can enforce time-of-day or shift-based access, and attribute-based access control (ABAC) can further limit contractor access based on attributes such as department assignment. This combination supports least privilege by granting only the minimum access needed based on role, contextual rules, and user/resource attributes, while keeping permission decisions under centralized administrative control rather than end users.

  • C. Incorrect.

    Incorrect. MAC is a highly restrictive model commonly associated with environments that use centrally assigned security labels and classifications, such as military or government systems. It does prevent users from granting access, but the statement that labels are assigned only by data owners is wrong because MAC relies on central authority, not owner discretion. It is also not the best fit for this business requirement because the scenario depends heavily on job role, time-based restrictions, and department-specific attributes.

  • D. Incorrect.

    Incorrect. Rule-based access control can enforce conditions such as time-of-day restrictions, but using only rules would not efficiently address differences in job function or department assignment. Nurses, physicians, and contractors have different business responsibilities, and those distinctions are better handled through roles and attributes. A candidate might pick this because shift-hour enforcement is prominent in the scenario, but rule-based controls alone are too limited.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam