For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeCPA®CPA ISC Practice Exam 3Question 78
    Easy1 markMultiple Choice
    Area II: SecurityAccess ControlIdentity Management

    CPA · Question 78 · Area II: Security

    A company uses 'Role-Based Access Control' (RBAC). How are permissions assigned?

    Answer options:

    A.

    Permissions are assigned directly to each user individually.

    B.

    Permissions are assigned to roles (e.g., 'Manager'), and users are assigned to roles.

    C.

    Permissions are based on the user's security clearance level (Top Secret).

    D.

    Permissions are based on time of day.

    How to approach this question

    User -> Role -> Permission.

    Full Answer

    B.Permissions are assigned to roles (e.g., 'Manager'), and users are assigned to roles.✓ Correct
    In RBAC, access rights are grouped by role name, and the use of resources is restricted to individuals authorized to assume the associated role. This simplifies administration compared to assigning rights to every user individually.

    Common mistakes

    Confusing RBAC with MAC (Clearance levels).
    Question 77All questionsQuestion 79

    Practice the full CPA ISC Practice Exam 3

    82 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A CPA is advising a client who is migrating their legacy on-premise ERP system to a cloud-based s...MediumQ02During a review of a client's cloud governance structure, an auditor notes that the client uses a...MediumQ03An auditor is evaluating the 'Processing Integrity' principle for a financial institution's loan ...HardQ04A company uses a batch processing system to update inventory records overnight. The 'Grandfather-...HardQ05During a walkthrough of the change management process, an auditor observes that the 'Developer' r...Medium
    View all 82 questions →