Repair inherited access and enforce conflicting-role boundaries

A hands-on CISSP lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CISSP practice

Certification
CISSP
Format
Structured configuration
Difficulty
medium
Estimated time
30 min
Automated checks
8

The brief

Edit role-review.json. roles contains unique {id,permissions,inherits}; assignments contains one {user,roles} for each supplied user; sessions contains one {id,user,activeRoles} for each supplied session, without changing its user. Referenced roles must exist and inheritance must be acyclic. Use only the seven supplied permission IDs. Bounds: at most 12 roles, 8 users and 12 sessions; each ID is ASCII letters, digits, hyphens or underscores, 1..60 characters. Arrays have no duplicate values. Repair all direct/transitive excess, current static assignment conflicts and current dynamic activation conflicts. Keep every required operation available: a rejected activation grants no permissions. separation has static and dynamic arrays of distinct two-permission pairs. Static needs [vendor-prepare,vendor-approve]; dynamic needs [invoice-prepare,invoice-approve]. Each may hold at most eight pairs. enforcement has assignment and activation, each reject or log. Log records a conflict but permits it. Future probes enumerate every role subset through actual inheritance; assignment proposals with a static conflict and authorized activation proposals with a dynamic conflict must be rejected. Safe current snapshots alone do not satisfy prevention. You may restructure role edges/permissions or redesign assignments; equivalent safe strategies are accepted. Legacy roles may remain unused. Review named failures, save partial progress, repair without Reset and rerun. Reset restores the unsafe starter. This simulated model permits different sessions for invoice duties and does not check per-invoice history.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • Typed complete users/sessions and bounded acyclic role references.
  • Every assigned-role closure fits its user's permission ceiling.
  • No existing user authorizes both vendor duties.
  • No current session activates both invoice duties through inheritance.
  • Every active role belongs to the user's authorized closure.
  • Every required session can execute its operation and read the ledger.
  • All future role sets with the supplied static conflict are rejected.
  • All authorized future activation sets with the invoice conflict are rejected.

Where this sits in the CISSP blueprint

Domain
Identity and Access Management (IAM)
Objective
Authorization Mechanisms
Skill
Roles, Attributes and Policy Enforcement

Part of CISSP preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.