CISSP Security Architecture and Engineering Practice Question
A security architect is evaluating access control models for a healthcare system where users have specific roles (e.g., doctor, nurse, admin) and permissions are assigned based on those roles. However, the architect also wants to incorporate attributes such as time of day, patient consent status, and device type. Which TWO models should be combined to meet these requirements?
⚠ Common exam trap
CISSP often tests the misconception that ABAC replaces RBAC — the trap is choosing only ABAC when the scenario explicitly requires role-based permissions plus contextual attributes, which mandates combining both.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ABAC
Option D (RBAC) is correct because the scenario explicitly states that users have specific roles such as doctor, nurse, and admin, and permissions are assigned based on those roles — this is the defining characteristic of Role-Based Access Control, where access rights are grouped into roles and users are assigned to roles. Option C (ABAC) is correct because the architect additionally wants to enforce dynamic, fine-grained conditions such as time of day, patient consent status, and device type, which are attributes evaluated at request time — exactly what Attribute-Based Access Control provides through policies combining subject, resource, action, and environmental attributes. Combining RBAC and ABAC (often called a hybrid or role-and-attribute model) lets roles provide coarse-grained baseline permissions while attributes refine decisions for context-sensitive healthcare access. Option A (Clark-Wilson) is not selected because it is an integrity model focused on well-formed transactions and separation of duties, not on role- or attribute-driven access decisions. Option B (MAC) is not selected because it relies on mandatory labels and clearances rather than the role and contextual attribute inputs described. Option E (DAC) is not selected because it grants resource owners discretionary control via ACLs, which does not satisfy the role-based and attribute-based requirements stated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Clark-Wilson
Why it's wrong here
Clark-Wilson is fundamentally an integrity model, not an access control model. Its primary objective is to maintain data integrity by preventing unauthorized modifications and ensuring internal and external consistency through well-formed transactions and separation of duties. While it dictates how data can be manipulated, it does not define the general rules for who can access what resources based on roles or attributes, which is the core function of an access control model.
- ✗
MAC
Why it's wrong here
Mandatory Access Control (MAC) operates on a strict, system-enforced policy where subjects and objects are assigned security labels, such as sensitivity levels and categories. Access is granted or denied based on a comparison of these labels, adhering to rules like "no read down" and "no write up." This model does not utilize roles or dynamic attributes for decision-making; instead, it relies on a rigid, predefined classification scheme enforced by the operating system or security kernel.
- ✓
ABAC
Why this is correct
Attribute-Based Access Control (ABAC) is a dynamic access control model that evaluates a set of attributes associated with the subject (user), object (resource), action (operation), and environment (context) to make real-time access decisions. This highly flexible approach allows for fine-grained control, enabling policies like "a manager in department X can approve expenses up to $500 during business hours." ABAC provides unparalleled granularity and adaptability, making it suitable for complex, evolving access requirements.
- ✓
RBAC
Why this is correct
Role-Based Access Control (RBAC) centralizes access management by assigning permissions to roles rather than directly to individual users. Users are then assigned to one or more roles, inheriting the permissions associated with those roles. This model simplifies administration, especially in large organizations, by aligning access privileges with job functions and organizational structure, ensuring that users only have the necessary permissions to perform their duties.
- ✗
DAC
Why it's wrong here
Discretionary Access Control (DAC) allows the owner of a resource to determine who can access it and what permissions they have. This model provides high flexibility for individual users but lacks centralized control and can lead to inconsistent security policies across an enterprise. DAC is generally unsuitable for environments requiring dynamic, organization-wide rules based on attributes, as it relies on individual discretion rather than a centrally enforced policy.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
MAC
MAC (Media Access Control) is a unique hardware identifier assigned to network interfaces for communication on a local network segment.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.