Enhance your Cisco Cyber Security knowledge. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your Cisco Cyber Security Exam with our comprehensive quiz!

Practice this question and more.


Which access control strategy allows only senior managers with high clearance to access the Finance Report?

  1. Mandatory access control

  2. Discretionary access control

  3. Role-based access control

  4. Rule-based access control

The correct answer is: Role-based access control

Role-based access control (RBAC) is the correct choice because it assigns permissions based on the roles of individual users within an organization. In this case, only senior managers with high clearance possess a role that allows them access to the Finance Report. This access control model effectively makes access decisions based on the roles assigned to users, ensuring that the principle of least privilege is enforced. RBAC simplifies management by allowing administrators to define access permissions centrally and assign them to different roles rather than to individual users. This is particularly effective in organizations with a clear hierarchical structure where specific roles, such as senior management, require elevated access to sensitive information like financial reports. In contrast, mandatory access control enforces regulations set by a central authority and does not allow individuals to change access settings. Discretionary access control allows users to control access to their own resources, which is not suitable in scenarios requiring stringent access such as financial data. Rule-based access control applies specific rules to allow or deny access, which lacks the role definition aspect critical for managing access for senior managers specifically.