Certified In Cybersecurity CC · Free Practice Question Easy
Question 5
Who dictates the access controls rules in a Discretionary Access Control (DAC)?
-
A
The last user who used the object
-
B
The subject who created the object
-
C
Only security administrators
-
D
The CEO or CISO of the company
Reveal correct answer
Correct answer: B
Explanation
In a Discretionary Access Control (DAC) model, the subject who created the object dictates the access control rules. This means that the owner of the information or resource has the discretion to determine who else can access it (see the ISC2 Study Guide, Domain 3).
For example, in a file-sharing system that uses a DAC model, a user who creates a file can decide who else can view, edit, or delete the file. You might allow some users to view the file but not edit it, while other users have full access.
The other options are incorrect because in a DAC model, security administrators, the last user to use the object, and the company's CEO or CISO do not dictate access control rules. In practice, the owner of the information or resource has that authority.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
