Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
In an organization where there are frequent personnel changes, non-discretionary access control using Role Based Access Control (RBAC) is useful because:
Correct Answer: B
Explanation/Reference: Explanation: With Non-Discretionary Access Control, a central authority determines what subjects can have access to certain objects based on the organizational security policy. The access controls may be based on the individual's role in the organization (role-based access control) or the subject's responsibilities and duties (task-based access control). In an organization where there are frequent personnel changes, non- discretionary access control is useful because the access controls are based on the individual's role or title within the organization. These access controls do not need to be changed whenever a new person takes over that role. Incorrect Answers: A: People not needing to use discretion is not the reason RBAC is useful in an organization where there are frequent personnel changes. C: With RBAC, the access controls ARE based on the individual's role or title within the organization. D: With RBAC, the access controls are ALWAYS based on the individual's role or title within the organization. References: Krutz, Ronald L. and Russell Dean Vines, The CISSP and CAP Prep Guide: Mastering CISSP and CAP, Wiley Publishing, Indianapolis, 2007, p. 48 http://csrc.nist.gov/groups/SNS/rbac/