Courseiva
Question 80 of 1,013
Security ArchitecturehardMultiple ChoiceObjective-mapped

Attribute-Based Access Control (ABAC) for Multi-Condition Access Policies

A contractor signs in to a project portal that fronts several SaaS tools. Access must be granted only if all of the following are true: the user is assigned to the project, the device is managed, and the request occurs during the approved maintenance window. Which access model best supports this requirement?

Quick Answer

The answer is attribute-based access control (ABAC) because it evaluates multiple runtime attributes—such as user-project assignment, device management status, and time of request—against a policy to grant access. Unlike role-based access control (RBAC), which only checks a static role, ABAC can combine subject, resource, and environment attributes in a single rule, making it the only model that satisfies all three simultaneous conditions. On the Security+ SY0-701 exam, this type of multi-condition scenario tests your ability to distinguish ABAC from RBAC, where a common trap is assuming a role alone can enforce device or time restrictions. Remember that ABAC is dynamic and context-aware, while RBAC is static and role-only. For a quick memory tip: think "ABAC = All conditions Before Access is Cleared."

⚠ Common exam trap

The trap here is that candidates see 'contractor' and 'project' and immediately think of RBAC roles, overlooking that the requirement explicitly demands evaluation of multiple runtime attributes (device managed, maintenance window) which only ABAC can handle dynamically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Attribute-based access control because multiple runtime attributes determine access

Attribute-based access control (ABAC) evaluates multiple runtime attributes—such as user-project assignment, device management status, and time of request—against policies to grant access. This matches the requirement because all three conditions must be true simultaneously, and ABAC can combine subject, resource, and environment attributes in a single policy rule. Role-based access control (RBAC) would only check the user's role, not device or time attributes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Role-based access control because the contractor has one project role

    Why it's wrong here

    RBAC can assign broad permissions based on a role, but it does not natively evaluate changing conditions like device posture, time window, or project assignment at each request. It is too coarse for this scenario.

  • Attribute-based access control because multiple runtime attributes determine access

    Why this is correct

    ABAC is the best fit because the decision depends on several attributes evaluated dynamically: user assignment, device status, and time of request. This lets the organization express a policy that is more precise than a static role and better aligned to least privilege. In a federated portal, ABAC can also work alongside identity assertions to make access decisions at sign-in and during session use.

  • Single sign-on because the user should not log in more than once

    Why it's wrong here

    SSO improves user convenience by reducing repeated logins, but it does not describe how access is authorized. The question is about the rule set that decides whether the user should be allowed in at all.

  • Privileged access management because the contractor needs temporary access

    Why it's wrong here

    PAM is useful for elevated administrative access and controlled privileged sessions, but this user is requesting conditional business access based on attributes. The scenario is not primarily about admin elevation or break-glass access.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A contractor signs in to a project portal that integrates several SaaS apps. Access should be granted only while the user is on a managed device, assigned to the project, and using a fresh second factor. The business also wants the contractor to avoid separate logins to each app. Which three controls best fit this design? Select three.

hard
  • A.Use federation or SSO so the identity provider issues the session for all approved apps.
  • B.Use ABAC or conditional access rules that check project assignment and device compliance.
  • C.Require MFA and step-up authentication before the contractor reaches sensitive functions.
  • D.Create a shared project account so access can be revoked by changing one password.
  • E.Issue long-lived refresh tokens that never expire unless the user reports a problem.

Why A: Federation or SSO (A) allows the identity provider to issue a single session token (e.g., SAML assertion or OIDC ID token) accepted by all integrated SaaS apps, eliminating separate logins while maintaining centralized session control. ABAC or conditional access rules (B) are essential for enforcing the specific conditions: the user must be on a managed device and assigned to the project, and these checks can be applied to each access request. MFA with step-up authentication (C) satisfies the requirement for a fresh second factor and adds stronger verification before the contractor reaches sensitive functions. The other options are incorrect: a shared account (D) undermines audit trails and cannot enforce per-user MFA/device compliance, and long-lived refresh tokens (E) contradict the need for fresh second factors and continuous device/project validation.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.