
Certified Information Systems Security Professional
Domain 5Objective 4
5.4 - Implement and Manage Authorization Mechanisms CISSP Practice Questions (Page 6)
Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
13%of the exam
Questions 26–28
- 26
A multinational company needs to control access to its cloud-based document management system. The policy requires that access be granted based on the user's department, the document's confidentiality level, and the user's current location (e.g., office vs. remote). The policy must be evaluated dynamically for each access request. Which access control model is most appropriate?
Select an answer first - 27
A small company uses a file server with DAC. The CEO wants to ensure that only the HR manager can access employee salary files, but the HR manager wants to be able to delegate access to a specific HR assistant. The CEO also wants to prevent the HR manager from granting access to anyone outside the HR department. Which approach best meets these requirements?
Select an answer first - 28
A university wants to ensure that only faculty members can access the grade entry system, and only during the final exam period. The IT department wants to avoid creating a separate role for each semester. Which combination of access control models would be most efficient?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.