What is the difference between Access Control Lists (ACLs) and Capability Tables?
Correct Answer: B
Explanation/Reference:
Explanation:
A capability table stipulates the access rights that a specified subject has in relation to detailed objects.
Access control lists defines subjects that are authorized to access a specific object, and includes the level of authorization that subjects are granted.
Therefore, the difference between the two is that the subject is bound to the capability table, while the object is bound to the ACL.
Incorrect Answers:
A: This is incorrect as access control lists are related/attached to an object, and capability tables are related/attached to a subject.
C: This is incorrect as access control lists are used for objects, and capability tables are for subjects.
D: access control lists and capability tables are not basically the same because one is bound to objects, and the other is bound to subjects.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 229-231