Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 53
ThorTeaches.com is implementing a new security system and needs to decide on a method for controlling access to sensitive information. Which of the following is a type of access control model that defines which individuals have access to what resources?
- A Virtual Private Network (VPN)
- B Discretionary Access Control (DAC)
- C Secure Sockets Layer (SSL)
- D Data Loss Prevention (DLP)
Reveal correct answer
Correct answer: B
Explanation
The correct answer: Discretionary Access Control (DAC): Discretionary Access Control (DAC) is a type of access control system that grants or restricts access to object (like files, data, etc.) based on the identity of the users and/or the groups to which they belong. The controls are discretionary in the sense that a subject with certain access permissions is capable of passing those permissions (perhaps indirectly) on to any other subject. The incorrect answers: Virtual Private Network (VPN): A VPN is a technology that creates a secure connection over a less-secure network between an organization's internal network and remote users. It's not an access control model but rather a method to ensure secure and private communication. Data Loss Prevention (DLP): DLP refers to a set of tools and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users. While it relates to security, it's not an access control model. Secure Sockets Layer (SSL): SSL is a protocol for establishing secure communication over computer networks. It's primarily used to encrypt the connection between a web user's browser and the web server. It's not an access control model, but a protocol for ensuring data confidentiality and integrity.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
