An organization is trying to decide which type of access control is most appropriate for the network. The current
access control approach is too complex and requires significant overhead. Management would like to simplify
the access control and provide user with the ability to determine what permissions should be applied to files,
document, and directories. The access control method that BEST satisfies these objectives is:
A.
Rule-based access control
B.
Role-based access control
C.
Mandatory access control
D.
Discretionary access control
Management would like to simplify the access control and “provide user with the ability to determine what permissions should be applied” to files, document, and directories.
The way i’m understanding this is that the Users will determine the access of file and directories….. so wouldn’t that be Discretionary Access Control???
I’m finding that some of these answers are incorrect so far… is it just me? are other disagreeing with some of these answers?
Agreed with D.
“DACs are discretionary because the subject (owner) can transfer authenticated objects or information access to other users. In other words, the owner determines object access privileges.”
https://www.techopedia.com/definition/229/discretionary-access-control-dac