A nondiscretionary access control technique based on a set of operational rules or restrictions to enforce a least privileges policy is known as which?

Prepare for the Information Security Principles and Frameworks Test. Enhance your understanding with detailed questions, hints, and explanations. Ace your exam with confidence!

Multiple Choice

A nondiscretionary access control technique based on a set of operational rules or restrictions to enforce a least privileges policy is known as which?

Explanation:
Rule-Based Access Control relies on a fixed set of operational rules that determine whether a subject can access a resource. Because decisions come from these predefined rules rather than user discretion, this approach is nondiscretionary and supports a least-privilege posture: access is granted only when the rules permit it, often considering conditions like time, location, or authentication level. This makes it the best fit for a description centered on a rule-driven mechanism enforcing restricted rights across the board. Access Control Lists are discretionary, letting owners grant permissions; Least Privilege is a guiding principle, not a mechanism; ABAC uses attributes and policies and can be rule-driven, but the standard terminology for a system defined by a fixed rule set is Rule-Based Access Control.

Rule-Based Access Control relies on a fixed set of operational rules that determine whether a subject can access a resource. Because decisions come from these predefined rules rather than user discretion, this approach is nondiscretionary and supports a least-privilege posture: access is granted only when the rules permit it, often considering conditions like time, location, or authentication level. This makes it the best fit for a description centered on a rule-driven mechanism enforcing restricted rights across the board. Access Control Lists are discretionary, letting owners grant permissions; Least Privilege is a guiding principle, not a mechanism; ABAC uses attributes and policies and can be rule-driven, but the standard terminology for a system defined by a fixed rule set is Rule-Based Access Control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy