Implementing Role-Based Access Control for Site Recovery

Identity and Access Management

A systems administrator wants to prevent users from being able to access data based on their responsibilities. The administrator also wants to apply the required access structure via a simplified format. Which of the following should the administrator apply to the site recovery resource group?

  1. RBAC Source Reference Answer
  2. ACL
  3. SAML
  4. GPO

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the distinction between identity-centric models (RBAC) and object-centric models (ACLs), with the common trap being confusion between GPOs for configuration management versus actual access control policies.

This question tests the ability to select Role-Based Access Control (RBAC) as the primary mechanism for managing permissions based on job responsibilities. The community consensus confirms RBAC is the standard solution for simplifying access structures while enforcing responsibility-based data restrictions.

Candidates often select ACL because it is a fundamental access control mechanism, but fail to recognize that ACLs are granular lists attached to objects, whereas RBAC provides the simplified, role-based structure requested for user responsibilities.

Community Discussion (4 comments)

MAKOhunter33333333 👍 12 Selected: A
Role-based access control (RBAC) restricts users to only access data based on their job responsibilities.
AutoroTink 👍 8 Selected: A
RBAC: Role-Based Access Control (Permissions based on roles. Others include: MAC, DAC, Rule-based, ABAC) ACL: Access Control List (Popular with configuring firewalls) SAML: Security Assertion Markup Language (used alongside SSO, authentication) GPO: Group Policy Objective (used in hardening, to dictate policies, user rights, and audit settings)
Syl0 👍 1
RBAC - Rule Based Access Control ACL - Access Control List SAML - Security Assertion Markup Language GPO - Group Policy Object
dbrowndiver 👍 2 Selected: A
In this question the best choice is "A". RBAC (Role-Based Access Control) is correct because it allows the systems administrator to prevent unauthorized access by defining roles and assigning permissions based on user responsibilities. RBAC simplifies the access management process and ensures that users only have access to the data necessary for their roles.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Role-Based Access Control (RBAC) is designed specifically to manage permissions by assigning them to roles rather than individual users. This approach directly addresses the requirement to restrict access based on 'responsibilities' and allows for a 'simplified format' of management, as administrators only need to assign users to predefined roles.

Why the Other Options Are Wrong

Access Control Lists (ACLs) are typically associated with network devices like firewalls or specific file system permissions, which can become complex to manage at scale. SAML is an authentication protocol used for Single Sign-On (SSO) and does not define authorization rules. Group Policy Objects (GPOs) are used for configuring Windows settings and security policies but are not the primary model for defining logical access responsibilities in this context.

Community Comment Notes

Comments [1], [2], and [3] unanimously support RBAC, highlighting its ability to restrict access based on job roles. Comment [2] provides excellent definitions for all options, clarifying that SAML is for authentication and GPO is for hardening/policy enforcement, which helps distinguish them from access control models.

Official Reference

Exam Strategy

When you see keywords like 'job responsibilities,' 'roles,' or 'simplified management,' immediately consider RBAC. Distinguish it from technical implementation tools like ACLs or protocols like SAML, focusing on the logical model of permission assignment.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide