The IT department has setup a share point site to be used on the intranet. Security has
established the groups and permissions on the site. No one may modify the permissions and all
requests for access are centrally managed by the security team. This is an example of which of
the following control types?

A.
Rule based access control
B.
Mandatory access control
C.
User assigned privilege
D.
Discretionary access control
Explanation:
Answer is wrong, Correct answer is D
0
0
Jason, discretionary access control means any user can assign permissions for files he/she owns. The question explicitly says that no one may modify permissions and they are all handled by the security team. That is the definition of mandatory access control.
0
0