3. Given the following RBAC policy configured for a small company, answer the fo
ID: 3873697 • Letter: 3
Question
3. Given the following RBAC policy configured for a small company, answer the following ques- tions Purchase-List, View Management Alice Bob Carol David Purchase-List, Edit Purchase-List, Approve Inventory, Edit Inventory, View Purchase Finance (a) What permission(s) does Alice have when she activates her "management" role? (b) Suppose we want to enforce the same policy in a system that only supports Access Control Lists (ACLs). Determine such ACLs. (Note that each permission in RBAC is a collection of an object and an action)Explanation / Answer
Alice will have permission to view,edit Purchase-List and view,edit Inventory.
If we are modeling the same policy using ACL
Create four users and three group,
Group1 Management having permission to Inventory,Edit.
Group2 Purchase having permission to Purchase-List,View Purchase-List,Edit, Inventory,View
Group3 Finance having persmission to Purchase-List,Approve
Alice will be assigned to Group1 and Group2
Bob will be assigned to Group2
Carol will be assigned to Group2 and Group3
David will be assigned to Group3
Related Questions
Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.