Which of the following is a type of mandatory access control?

A.
Rule-based access control
B.
Role-based access control
C.
User-directed access control
D.
Lattice-based access control
Explanation:
Reference: pg 46 Krutz: CISSP Prep Guide: Gold Edition
Actually LBAC (Lattice Based AC) also is a MAC. Here is some info:
“Another MAC-based model is the Lattice-based access control model. It shares with the Bell-LaPadula model the idea that objects and users are each given a hierarchical security level label, and that you determine whether or not a user has access to an object, by comparing their labels. As with Bell-LaPadula, if the user’s clearance level is at or above the classification level of the object, access is permitted. ”
http://www.certiguide.com/secplus/cg_sp_111MandatoryAccessControlMAC.htm
0
0
Agree
0
0
Wrote CISSP exam few days ago and finally passed!
A few scenarios and many management type of questions! Most of questions can be found from PassLeader CISSP dumps — http://www.passleader.com/cissp.html
P.S. The CISSP is much easier than the CISM.
Good Luck for All!
0
0