Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Compare

MAC vs DAC vs RBAC

MAC, DAC, and RBAC are the access control models on the SY0-701 exam. They differ in who decides access and how rigid that decision is. The exam loves to give a scenario and ask which model it describes.

Last updated August 2026

MAC vs DAC vs RBAC side by side
AspectMACDACRBAC
Full nameMandatory Access ControlDiscretionary Access ControlRole-Based Access Control
Who sets accessThe system, centrally, by policyThe data owner, at their discretionAn administrator, by job role
Based onSecurity labels and clearance levelsOwner choices, via ACLsThe role or job function of the user
FlexibilityRigid, very strictFlexible, user controlledStructured, scales with the org
Typical useMilitary, government, high-security systemsMost commercial operating systemsEnterprises and large organizations
ExampleA Top Secret file is readable only with Top Secret clearanceA user shares a file they own with a colleagueA Nurse role grants access to patient records

The bottom line

MAC is enforced by the system with labels and clearances (most rigid), DAC lets the owner decide (most flexible), and RBAC assigns access by job role (scales best). The exam also references ABAC (attribute-based) and rule-based access control.

Lock it in with practice

Reading the difference is a start. SecPlus Mastery drills it with over 1,000 practice questions, timed mock exams, and spaced review across all five SY0-701 domains, so it sticks for exam day.

New accounts get 30% off both plans for 7 days: the 90-Day Pass is $27.30 instead of $39.

FAQ

  • What is the difference between MAC and DAC?
    In MAC the system enforces access using labels and clearances, and users cannot change them. In DAC the resource owner decides who gets access, which is more flexible but easier to misconfigure.
  • Is RBAC the same as rule-based access control?
    No, though both are abbreviated RBAC. Role-based control grants access by job role; rule-based control applies conditions such as time of day or source IP. The exam distinguishes the two.

More Security+ comparisons

Compare Security+ to other certifications

Written to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.