問題文
Two systems at a defense supplier handle permissions differently. On the shared drive, the person who creates a folder grants others access to it. On the classified system, every file and every user carries a sensitivity marking and the system compares them. Which models are these?
選択肢
- Both use attribute-based access control, because a sensitivity marking is an attribute.
- The shared drive uses discretionary access control because the owner decides, and the classified system uses mandatory access control because the system enforces a comparison of markings that no user may override.
- The shared drive uses mandatory access control because the organization mandates that creators take responsibility, and the classified system uses discretionary control because an officer assigns each marking.
- Both use role-based access control, because in both cases what a person may reach depends on the position that person holds in the supplier's organization.