Study. uk . com
  1. Home
  2. All questions
  3. Question 324

CompTIA Security+ study material · question 324 of 611

An access requirement changes and the team struggles to find every place it was implemented. Which models does NIST warn about for this reason?

  1. Attribute-based and rule-based
  2. Access control lists and role-based access control
  3. Zero trust and microsegmentation
  4. Mandatory and discretionary
Show the answer

Answer: B. Access control lists and role-based access control

With no central policy expression, the requirement is scattered across many list entries and role definitions.

Source: NIST SP 800-162 (NIST) — SP 800-162 § 2.1

Challenge yourself on this topic → Study as cards