Curriculum
Total Questions: 25 | Time Recommended: 45 minutes
SECTION A: MULTIPLE CHOICE (Questions 1–20)
Q1: In the Discretionary Access Control (DAC) model, who is ultimately
responsible for determining access rights to a resource?
A) The system administrator
B) The resource owner
C) The security officer
D) The operating system kernel
Answer: B
Explanation: In DAC, the owner of a resource (such as a file creator) has the
discretion to grant or revoke access permissions to other users, typically
implemented through Access Control Lists (ACLs).
Q2: Which access control model uses security labels and is primarily designed to
enforce confidentiality by preventing users from reading data at a higher
classification level?
A) RBAC
B) MAC (Mandatory Access Control)
C) ABAC
D) DAC
Answer: B
Explanation: MAC uses system-enforced security labels (e.g., Top Secret, Secret,
Confidential) and follows the Bell-LaPadula model's "no read up, no write down"
principle to protect confidentiality.
Q3: In the Bell-LaPadula model, the Simple Security Property (ss-property) states
that a subject cannot:
A) Read data at a lower classification level
, B) Read data at a higher classification level
C) Write data to a higher classification level
D) Execute programs at any classification level
Answer: B
Explanation: The ss-property, or "no read up," prevents subjects from reading
objects at a higher security classification, ensuring users cannot access more
sensitive data than their clearance allows.
Q4: A large hospital implements access control where physicians, nurses, and
billing staff each receive permissions based on their job function. This is an
example of:
A) DAC
B) MAC
C) RBAC (Role-Based Access Control)
D) Rule-Based Access Control
Answer: C
Explanation: RBAC assigns permissions based on predefined roles (e.g.,
physician, nurse, billing staff) rather than individual identities, simplifying
administration in large organizations.
Q5: An organization needs to grant access to a sensitive database only during
business hours, from corporate IP addresses, and only on managed devices.
Which access control model best supports these requirements?
A) DAC
B) MAC
C) RBAC
D) ABAC (Attribute-Based Access Control)
Answer: D
Explanation: ABAC evaluates dynamic attributes including user identity, resource
sensitivity, environmental conditions (time, location), and device posture to make
granular, context-aware access decisions.
Q6: A firewall that permits HTTP traffic on port 80 but blocks all other inbound
connections is implementing which type of access control?