CISSP-ISSAP Exam: Discretionary Access Control List (DACL) Truths

Discretionary Access Control List (DACL)

Question

Which of the following statements about Discretionary Access Control List (DACL) is true?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

The correct answer is D. It is a rule list containing access control entries.

Explanation: Discretionary Access Control List (DACL) is a security mechanism used in computer systems that control access to resources based on user identity and the permissions assigned to them. It is a list of access control entries that specify which users, groups, or computers are granted or denied access to a resource. DACL is associated with an object, such as a file or a folder, and it determines who can access that object and what level of access they have.

Option A, "It specifies whether an audit activity should be performed when an object attempts to access a resource," is incorrect because this is the function of an Audit Access Control List (SACL), not a DACL.

Option B, "It is a unique number that identifies a user, group, and computer account," is incorrect because this describes a security identifier (SID), not a DACL.

Option C, "It is a list containing user accounts, groups, and computers that are allowed (or denied) access to the object," is partially correct because it describes the contents of a DACL, but it does not fully explain what a DACL is. A DACL is a rule list containing access control entries that specify which users, groups, or computers are granted or denied access to a resource.