Which statement about RBAC is correct?

Prepare for the TAMIS Certification Test with our comprehensive quiz. Study using flashcards and multiple-choice questions, each with hints and explanations. Excel in your examination!

Multiple Choice

Which statement about RBAC is correct?

Explanation:
RBAC works by assigning permissions to roles rather than to individuals, and users gain access by assuming those roles. This setup enforces the principle of least privilege because each user only has the rights their role requires, reducing unnecessary access to sensitive data or actions. It also offers strong traceability: you can see which roles exist, which users hold them, and exactly what resources and operations each role can access, making it easier to audit and identify who did what. The other statements don’t fit because granting all features to everyone would violate least privilege, RBAC does have a meaningful impact on security by limiting access and enabling audits, and RBAC does not replace QA, which is about testing and quality assurance rather than access control. In a TAMIS context, this means keeping inventory, approvals, and sensitive transactions restricted to appropriately defined roles with clear audit trails.

RBAC works by assigning permissions to roles rather than to individuals, and users gain access by assuming those roles. This setup enforces the principle of least privilege because each user only has the rights their role requires, reducing unnecessary access to sensitive data or actions. It also offers strong traceability: you can see which roles exist, which users hold them, and exactly what resources and operations each role can access, making it easier to audit and identify who did what.

The other statements don’t fit because granting all features to everyone would violate least privilege, RBAC does have a meaningful impact on security by limiting access and enabling audits, and RBAC does not replace QA, which is about testing and quality assurance rather than access control. In a TAMIS context, this means keeping inventory, approvals, and sensitive transactions restricted to appropriately defined roles with clear audit trails.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy