An e-commerce platform needs to control access to customer data based on the geographic location of the customer support staff. Only employees located in specific regions should have access to customer information from those regions. Which access control model is suitable for this scenario?a.Discretionary Access Control (DAC)b.Mandatory Access Control (MAC)c.Role-Based Access Control (RBAC)d.Attribute-Based Access Control (ABAC)
Question
An e-commerce platform needs to control access to customer data based on the geographic location of the customer support staff. Only employees located in specific regions should have access to customer information from those regions. Which access control model is suitable for this scenario?a.Discretionary Access Control (DAC)b.Mandatory Access Control (MAC)c.Role-Based Access Control (RBAC)d.Attribute-Based Access Control (ABAC)
Solution
The most suitable access control model for this scenario is Attribute-Based Access Control (ABAC). This model uses attributes as building blocks in a structured language to evaluate and enforce access control. Attributes can be related to the user, the object (in this case, customer data), or the environment (in this case, geographic location). In this scenario, the geographic location of the customer support staff can be used as an attribute to control access to customer data. Therefore, only employees located in specific regions will have access to customer information from those regions.
Similar Questions
Which of the following access control methodologies can be described BEST as allowing a user the least access based on the jobs the user needs to perform?Scope-basedRole-basedLocation-basedRule-based
Which access control model is commonly used in government and military environments, where access is based on security clearances and labels?a.Role-Based Access Control (RBAC)b.Attribute-Based Access Control (ABAC)c.Mandatory Access Control (MAC)d.Discretionary Access Control (DAC)
What type of security model allows the data or resource owner to grant or revoke access to other users?Mandatory Access Control (MAC)Role-based access control (RBAC)Attribute-based access control (ABAC)Discretionary Access Control (DAC)
You are reviewing access control models and want to implement a model that allows the owner of an object to grant privileges to other users. Which of the following meets this requirement?Group of answer choicesRole-Based Access Control (RBAC) modelMandatory Access Control (MAC) modelRule-based access control modelDiscretionary Access Control (DAC) model
Which of the following access control models make use of the classification levels of the information along with the subject’s clearance level?Group of answer choicesMandatory Access Control (MAC)Lattice-Based Access Control (LBAC)Attribute-Based Access Control (ABAC)Both MAC and LBAC
Upgrade your grade with Knowee
Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.