1) Employees in a large multinational organization frequently travel among various geographic locations. Which type of authorization policy BEST addresses this practice?
A. Multilevel
B. Identity
C. Role-based
D. Discretionary
Correct Answer: B
-------------------------------------------------
2) Which of the following is the BEST type of access control for an organization with employees who move between departments?
A. Mandatory
B. Role-based
C. Identity
D. Discretionary
Correct Answer: C
______________________
Note
■ Excuse me if I ask you 2 questions but, as you can see, they
are 2 questions of practically the same type
■ The official answer for both is always the same: "Entity"
(referring to "I believe" in IAM).
■ I immediately say that the answers can also be wrong
(this is not the first time)
■ My question is this: In my opinion, IAM (Identity management) is
fine when integration between different "Directories" is needed.
For this reason, I believe that for both questions the correct
answer is RBAC (Role-based access control).
■ What do you think about it? Can you help me understand?
Thank you so much!
Many thanks!
The answer for both the questions is Identity , following are the reasons :
Role is usually a extension of the persons identity , for example a person can have many roles but he only has one identity , roles can also be assigned temporarily thereby making role based access control a bit less effiecent when employee are moving from geographic location and also the credientials of the users are linked to their identities not to their roles so it has to be identity access management.
Get Answers For Free
Most questions answered within 1 hours.