✅ The verified answer to this question is available below. Our community-reviewed solutions help you understand the material better.
All this talk about these role-based versus attribute-based stuff is confusing. I quite like the "Cedar Design Pattern" approach of mapping the rules into the following classes (and what distinguishes them is the type of additional information they rely on):
. These cover classic role-based permissions. The rule relies on a group membership relation (who belongs in which group) that is defined externally.
Then, attributes can be used to implement these rules and augment with specific capabilities. Select what kind of permissions are used in the rules expressed below; some of these require membership information about the principal as well as relationships between resources and the groups.
Get Unlimited Answers To Exam Questions - Install Crowdly Extension Now!