GSEC Access Control and Password Management Practice Question
A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)
⚠ Common exam trap
The trap here is conflating RBAC with ABAC, assuming that role assignments alone can incorporate environmental conditions like time of day, which they cannot without additional attribute-based logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy-Based Access Control (PBAC)
Attribute-Based Access Control and Policy-Based Access Control both support dynamic, fine-grained access decisions using attributes and environmental conditions. They allow centralized policy management and auditing, which are critical for the financial institution. RBAC, MAC, and DAC lack the necessary flexibility and context-awareness. Therefore, ABAC and PBAC are the correct choices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
RBAC assigns permissions to roles rather than individual users, simplifying administration. However, it does not natively support dynamic decisions based on environmental conditions like time of day or resource attributes. While RBAC can be extended with constraints, it lacks the fine-grained, attribute-driven policy evaluation required here. The scenario demands real-time contextual evaluation, which RBAC alone does not provide.
- ✗
Mandatory Access Control (MAC)
Why it's wrong here
MAC enforces access based on security labels and clearances, typically used in military or high-security environments. It is rigid and centrally controlled, but it does not easily accommodate dynamic environmental attributes like time of day. While MAC provides strong confidentiality, it lacks the flexibility and fine-grained, context-based policy evaluation needed for the trading floor scenario.
- ✗
Discretionary Access Control (DAC)
Why it's wrong here
DAC allows resource owners to set permissions at their discretion. It is not centralized and does not support dynamic, attribute-based decisions. In a trading floor, DAC would lead to inconsistent policies and potential security gaps. It cannot enforce environmental conditions or provide the centralized auditing and policy management required. Thus, it does not meet the stated requirements.
- ✓
Policy-Based Access Control (PBAC)
Why this is correct
PBAC uses policies that can incorporate a wide range of attributes and conditions, including environmental factors. It centralizes policy management and enables dynamic, fine-grained access decisions. Often considered an evolution of ABAC, PBAC explicitly emphasizes policy-driven evaluation. It fits the requirement for centralized policy management and auditing, and supports context-aware decisions such as time-of-day restrictions.
- ✓
Attribute-Based Access Control (ABAC)
Why this is correct
ABAC evaluates policies using attributes of the subject, object, action, and environment. This enables dynamic, fine-grained decisions such as allowing access only during trading hours or from specific IP ranges. It supports centralized policy management through a policy decision point and can incorporate environmental conditions. ABAC aligns perfectly with the requirement for context-aware, attribute-driven access control.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.