Certified In Cybersecurity CC · Free Practice Question Easy

Question 5

Who dictates the access controls rules in a Discretionary Access Control (DAC)?

  • A

    The last user who used the object

  • B

    The subject who created the object

  • C

    Only security administrators

  • D

    The CEO or CISO of the company

Reveal correct answer

Correct answer: B

Explanation

In a Discretionary Access Control (DAC) model, the subject who created the object dictates the access control rules. This means that the owner of the information or resource has the discretion to determine who else can access it (see the ISC2 Study Guide, Domain 3).

For example, in a file-sharing system that uses a DAC model, a user who creates a file can decide who else can view, edit, or delete the file. You might allow some users to view the file but not edit it, while other users have full access.

The other options are incorrect because in a DAC model, security administrators, the last user to use the object, and the company's CEO or CISO do not dictate access control rules. In practice, the owner of the information or resource has that authority.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need