Access Control for Interim Human Resources Manager | File Server Configuration

Configuring Access Control for Interim Human Resources Manager

Prev Question Next Question

Question

A server administrator is configuring access control on a file server for an organization.

The Human Resources manager is taking a leave of absence for three months, during which time an interim Human Resources manager will take over the duties of the position.

Which of the following types of access control should be configured on the file server?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

D.

The type of access control that should be configured on the file server in this scenario is DAC (Discretionary Access Control).

DAC is a type of access control where the owner of a resource has discretion over who is granted access to that resource. In other words, the owner can grant or revoke access to the resource at their own discretion.

In this scenario, the Human Resources manager is the owner of the HR-related files on the file server, and therefore has the discretion to grant access to those files to the interim Human Resources manager. The server administrator can configure the file server to enforce DAC by assigning file permissions to the Human Resources manager and the interim manager. The interim manager's access can be granted based on their need to access the files, and their access can be revoked when their temporary position is over.

The other access control types listed in the question are:

  • MAC (Mandatory Access Control): This type of access control is used in environments where the security requirements are very high and are set by a central authority, rather than the resource owner. MAC is not appropriate for this scenario.
  • CBAC (Context-Based Access Control): This type of access control uses context, such as the time of day or the user's location, to determine whether access should be granted. CBAC is not appropriate for this scenario.
  • RBAC (Role-Based Access Control): This type of access control assigns access based on the user's role in the organization. RBAC could be used in this scenario if the interim Human Resources manager has a predefined role with the necessary permissions, but DAC is still more appropriate since it gives the owner of the resource more control over access.