In a capability-based access control model, which statement describes a capability?

Study for the PY103.16 Physical Security Test with flashcards and multiple-choice questions. Each question includes hints and explanations to help you prepare confidently and effectively. Get ready to ace your exam with our comprehensive study resources!

Multiple Choice

In a capability-based access control model, which statement describes a capability?

Explanation:
In capability-based access control, access is granted by possessing a capability—a token or reference that encodes the specific rights to an object. This capability explicitly states what operations are allowed (for example, read or write) on that particular object and may include constraints like time limits or scope. Because possession of the capability itself grants access, it can be carried and presented to access the resource without checking a central policy each time. The other ideas don’t describe a capability: a record of roles is how RBAC assigns access, not a portable right token; a physical badge is a physical access control method, not a digital capability; a policy that denies all access by default reflects a default-deny rule, not a capability issued for a specific object and set of operations.

In capability-based access control, access is granted by possessing a capability—a token or reference that encodes the specific rights to an object. This capability explicitly states what operations are allowed (for example, read or write) on that particular object and may include constraints like time limits or scope. Because possession of the capability itself grants access, it can be carried and presented to access the resource without checking a central policy each time.

The other ideas don’t describe a capability: a record of roles is how RBAC assigns access, not a portable right token; a physical badge is a physical access control method, not a digital capability; a policy that denies all access by default reflects a default-deny rule, not a capability issued for a specific object and set of operations.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy