An organization requires that users authenticate via a smart card and a PIN to access secure network resources. Which access control model is being enforced?
Trap 1: Role-Based Access Control
Role-Based Access Control focuses on assigning permissions based on organizational functions and job duties rather than the authentication method itself. While smart cards can be used within an RBAC system, the requirement for dual-factor authentication describes the authentication mechanism rather than the architectural model for managing user permissions.
Trap 2: Discretionary Access Control
Discretionary Access Control allows the owner of a resource to set access policies based on user identity or group membership. This model is primarily concerned with permission management rather than the underlying authentication process, meaning the use of a smart card and PIN is unrelated to the DAC framework.
Trap 3: Mandatory Access Control
Mandatory Access Control governs access based on system-defined security labels and classifications for subjects and objects. It is a highly restrictive model typically found in government or military environments, but it does not inherently dictate the specific authentication factors used to verify the identity of the subjects involved.
- A
Role-Based Access Control
Why it fails: Role-Based Access Control focuses on assigning permissions based on organizational functions and job duties rather than the authentication method itself. While smart cards can be used within an RBAC system, the requirement for dual-factor authentication describes the authentication mechanism rather than the architectural model for managing user permissions.
- B
Discretionary Access Control
Why it fails: Discretionary Access Control allows the owner of a resource to set access policies based on user identity or group membership. This model is primarily concerned with permission management rather than the underlying authentication process, meaning the use of a smart card and PIN is unrelated to the DAC framework.
- C
Multifactor Authentication
Multifactor authentication requires two or more independent credentials to verify a user's identity, such as something you have and something you know. This significantly increases security compared to single-factor systems, as an attacker would need to compromise multiple distinct forms of authentication to gain unauthorized access to the environment.
- D
Mandatory Access Control
Why it fails: Mandatory Access Control governs access based on system-defined security labels and classifications for subjects and objects. It is a highly restrictive model typically found in government or military environments, but it does not inherently dictate the specific authentication factors used to verify the identity of the subjects involved.