5.0 Identity and Access Management

Access Control Models & Federation Practice Questions

DAC, MAC, RBAC and ABAC, Kerberos, RADIUS vs. TACACS+, SSO, SAML, and OAuth vs. OpenID Connect.

One solved question, so you can see how these are marked

A research organization must prevent users from changing the classification of documents, even when a user owns a document. Which access control model BEST supports this requirement?

Mandatory access control, because system-enforced labels govern subjects and objects

Mandatory access control uses centrally enforced labels and classifications, so an owner cannot override policy. DAC gives owners discretion, RBAC grants permissions through roles, and generic rule-based control does not inherently provide the label lattice required here.

Every question in the set below is marked like this. The answers stay hidden until you pick one.