CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 157


An organization would like to ensure that all new users have a predefined departmental access template applied upon creation. The organization would also like additional access for users to be granted on a per-project basis. What type of user access administration is BEST suited to meet the organization's needs?

Show Answer
Correct Answer: B

The best user access administration type to meet the organization's needs is Hybrid. In a hybrid approach, centralized control provides predefined departmental access templates for new users upon creation, ensuring consistency. Simultaneously, decentralized control allows additional access to be granted on a per-project basis, providing the necessary flexibility for specific project needs. This combination balances the stability of centralized administration with the adaptability of decentralized control.

Discussion

14 comments
Sign in to comment
OppenheimerOption: B
Oct 11, 2022

Agree with B it is a hybrid of RBAC and ABAC

jackdryan
May 13, 2023

B is correct

RVoigtOption: B
Mar 3, 2023

CISSP Official Student Guide pg 169 "Hybrid: In a hybrid approach, centralized control is exercised for some information and decentralized control is allowed for other information. One typical arrangement is that central administration is responsible for the broadest and most basic access, and the creators/owners of files control the types of access or users’ abilities for the files under their control. For example, when a new employee is hired into a department, a central administrator might provide the employee with access permissions based on the functional element they are assigned to, the job classification and the specific task they were hired to work on. The employee might have readonly access to an organization-wide SharePoint document library and to project status report files but read-and-write privileges to his department’s weekly activities report. Also, if the employee leaves a project, the project manager can easily close that employee’s access to that file."

StevoooOption: D
Sep 5, 2022

Can someone justify this answer please

kurtvon
Nov 9, 2022

Only: Because the test said so... (This question is a bad question)

mrgodOption: B
Sep 13, 2022

The question is talking about inside organization, so this is nothing to do with Federate..I think hybrid is a better choice.

NcoaOption: B
Oct 2, 2022

Agree with B it is a hybrid of RBAC and ABAC

Dee83Option: B
Jan 24, 2023

B. Hybrid user access administration is BEST suited to meet the organization's needs. Hybrid user access administration is a combination of both centralized and decentralized access administration. It allows for a predefined departmental access template to be applied to new users upon creation, which is a centralized approach. And also allows for additional access to be granted on a per-project basis, which is a decentralized approach. This allows for a balance between centralized control and flexibility for departments and project teams to manage their own access needs.

GPrepOption: C
Dec 18, 2023

I believe the answer is C. Hybrid and Federated refer to the back end solution for IAM, including SSO, etc. See page 688 of the official study guide "Hybrid Environment". According to pg 659, there are two options for Identity Management, Centralized and Decentralized. Therefore, I choose C.

homeyslOption: C
Mar 17, 2024

Why B? Hybrid is both on-prem and cloud. I didn't see anything about cloud in the question.

stickerbush1970Option: A
Sep 13, 2022

I would go with A

Cww1Option: B
Sep 19, 2022

agree with B https://www.serverbrain.org/infrastructure-design-2003/identifying-the-hybrid-administration-model.html

BoZTOption: B
Sep 3, 2023

Combination of RBAC and ABAC, ABAC can be per project basis.

maawar83Option: B
Dec 28, 2023

B It Is!

Vasyamba1Option: C
Mar 23, 2024

I go with C. OSG - Centralized access control implies that a single entity within a system performs all authorization verification.

Dtony66Option: B
May 3, 2024

How could it be D when Federated refers to inter organizational?