A security administrator at a hospital is establishing access controls for the patient records system. Which of the following approaches BEST implements security best practices for minimizing unnecessary access?
Implementing mandatory access controls based on security clearance levels for hospital staff
Providing physicians access to patient records relevant to their cases in the hospital to ensure continuity of care
Requiring multi-factor authentication for users accessing the electronic health records system based on their access level
Implementing function-specific permissions that restrict each user to accessing patient records required for their job responsibilities
The correct answer implements role-based access controls limiting users to accessing patient records required for their specific job function. This directly applies the principle of least privilege by restricting access rights to the minimum necessary for legitimate job duties.
Role-based access control supports this principle by defining access based on job functions rather than granting excessive permissions. The other options fail to implement least privilege because they either provide excessive access (physicians accessing records beyond their immediate need), use an inappropriate access model (mandatory access controls), or focus on authentication rather than authorization (multi-factor authentication verifies identity but doesn't restrict authorized access).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is role-based access control (RBAC)?
Open an interactive chat with Bash
What does the principle of least privilege mean?
Open an interactive chat with Bash
Why is multi-factor authentication (MFA) important in access control?
Open an interactive chat with Bash
ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access