
Certified Information Systems Security Professional
Domain 5Objective 4
5.4 - Implement and Manage Authorization Mechanisms CISSP Practice Questions (Page 2)
Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
13%of the exam
Questions 6–10
- 6
A hospital is implementing a new electronic health record (EHR) system. The compliance team requires that access to patient records be granted based on the user's job function (e.g., nurse, physician, pharmacist) and that no individual user can grant access to another user. The system must also enforce that a user's permissions are automatically updated when their job role changes. Which access control model should the hospital implement?
Select an answer first - 7
In Attribute-Based Access Control (ABAC), what is the basis for making access decisions?
Select an answer first - 8
Which of the following best describes the relationship between role assignment and permission authorization in RBAC?
Select an answer first - 9
In Mandatory Access Control (MAC), what determines whether a subject can access an object?
Select an answer first - 10
A multinational corporation is implementing a new ERP system. The security team must ensure that users in the finance department can access financial modules, but only during business hours in their local time zone. The company also wants to minimize administrative overhead by avoiding the creation of separate roles for each time zone. Which approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.