Study. uk . com
  1. Home
  2. All questions
  3. Question 367

CompTIA Security+ study material · question 367 of 611

Which requirement can attribute-based rules express that roles cannot?

  1. Grant access to any authenticated user
  2. Deny access outside business hours
  3. Grant access only to members of the finance role
  4. Grant access only when the subject's department matches the record's owning department
Show the answer

Answer: D. Grant access only when the subject's department matches the record's owning department

The rule compares an attribute of the subject with an attribute of the object, which a static role cannot capture.

Source: NIST SP 800-162 (NIST) — SP 800-162 § 2.2

Challenge yourself on this topic → Study as cards