Courseiva

GSEC Access Control and Password Management Practice Question

A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)

⚠ Common exam trap

The trap here is conflating RBAC with ABAC, assuming that role assignments alone can incorporate environmental conditions like time of day, which they cannot without additional attribute-based logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy-Based Access Control (PBAC)

Attribute-Based Access Control and Policy-Based Access Control both support dynamic, fine-grained access decisions using attributes and environmental conditions. They allow centralized policy management and auditing, which are critical for the financial institution. RBAC, MAC, and DAC lack the necessary flexibility and context-awareness. Therefore, ABAC and PBAC are the correct choices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-Based Access Control (RBAC)

    Why it's wrong here

    RBAC assigns permissions to roles rather than individual users, simplifying administration. However, it does not natively support dynamic decisions based on environmental conditions like time of day or resource attributes. While RBAC can be extended with constraints, it lacks the fine-grained, attribute-driven policy evaluation required here. The scenario demands real-time contextual evaluation, which RBAC alone does not provide.

  • ✗

    Mandatory Access Control (MAC)

    Why it's wrong here

    MAC enforces access based on security labels and clearances, typically used in military or high-security environments. It is rigid and centrally controlled, but it does not easily accommodate dynamic environmental attributes like time of day. While MAC provides strong confidentiality, it lacks the flexibility and fine-grained, context-based policy evaluation needed for the trading floor scenario.

  • ✗

    Discretionary Access Control (DAC)

    Why it's wrong here

    DAC allows resource owners to set permissions at their discretion. It is not centralized and does not support dynamic, attribute-based decisions. In a trading floor, DAC would lead to inconsistent policies and potential security gaps. It cannot enforce environmental conditions or provide the centralized auditing and policy management required. Thus, it does not meet the stated requirements.

  • ✓

    Policy-Based Access Control (PBAC)

    Why this is correct

    PBAC uses policies that can incorporate a wide range of attributes and conditions, including environmental factors. It centralizes policy management and enables dynamic, fine-grained access decisions. Often considered an evolution of ABAC, PBAC explicitly emphasizes policy-driven evaluation. It fits the requirement for centralized policy management and auditing, and supports context-aware decisions such as time-of-day restrictions.

  • ✓

    Attribute-Based Access Control (ABAC)

    Why this is correct

    ABAC evaluates policies using attributes of the subject, object, action, and environment. This enables dynamic, fine-grained decisions such as allowing access only during trading hours or from specific IP ranges. It supports centralized policy management through a policy decision point and can incorporate environmental conditions. ABAC aligns perfectly with the requirement for context-aware, attribute-driven access control.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.