Enhance your Cisco Cyber Security knowledge. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your Cisco Cyber Security Exam with our comprehensive quiz!

Practice this question and more.


What access control method restricts access to files relating to employee contracts only to HR Managers?

  1. Mandatory access control

  2. Role-based access control

  3. Discretionary access control

  4. Rule-based access control

The correct answer is: Role-based access control

Role-based access control (RBAC) is the appropriate access control method for restricting access to files, such as employee contracts, solely to HR Managers. This model assigns permissions to users based on their roles within an organization. Each role in RBAC has defined access rights, ensuring that only individuals in specific positions, like HR Managers, can access sensitive information related to employee contracts. The focus on roles allows for streamlined management of access permissions. When an employee's role changes, their access rights can be adjusted accordingly, facilitating a consistent and secure approach to data protection. This is especially critical in environments where different departments require varying levels of access to confidential information. In contrast, mandatory access control typically enforces a policy whereby access rights are assigned based on regulations and classifications, limiting the flexibility seen in RBAC. Discretionary access control allows owners of data to decide who can access their information, which can lead to less stringent control in sensitive scenarios. Rule-based access control applies predefined rules to grant access, but it's not as role-customized as RBAC. Thus, RBAC is best suited for managing access to files specifically for HR Managers.