Question 1 of 30
A financial services company is implementing a new identity and access management (IAM) system to enhance security and compliance with regulations such as GDPR and PCI DSS. The company needs to ensure that only authorized personnel can access sensitive customer data. They decide to implement role-based access control (RBAC) and attribute-based access control (ABAC) to manage user permissions effectively. In this context, which approach would best ensure that access to sensitive data is granted based on both the user\'s role and specific attributes, such as location and time of access?
Implementing a hybrid model that combines RBAC and ABAC to leverage the strengths of both systems.
Solely relying on RBAC to manage access permissions based on predefined roles without considering user attributes.
Using ABAC exclusively, which may lead to overly complex policies that are difficult to manage and audit.
Creating a static access control list (ACL) that does not adapt to changes in user roles or attributes.

Preparing for SalesForce Certified Identity and Access Management Architect Certified Identity and Access Management Architect? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free