RBAC vs ABAC Interview Questions and Answers
Top 10 RBAC vs ABAC interview questions with diagrams, production scenarios, and enterprise best practices.
Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) are the two most common authorization models used in enterprise applications. RBAC is simple and role-centric, whereas ABAC provides fine-grained access control using multiple attributes.
Q1. What is Role-Based Access Control (RBAC)?
Answer
RBAC is an authorization model where permissions are assigned to roles, and users inherit permissions by becoming members of those roles.
RBAC Diagram
User
│
▼
CUSTOMER
│
▼
View Account
Transfer Money
Example
| Role | Permissions |
|---|---|
| Customer | View Account, Transfer Money |
| Manager | Approve Loan |
| Admin | Manage Users |
Advantages
- Easy to implement
- Easy to manage
- Widely used
- Supported by Spring Security
Q2. What is Attribute-Based Access Control (ABAC)?
Answer
ABAC grants access based on multiple attributes instead of predefined roles.
Attributes may include:
- User Attributes
- Resource Attributes
- Environment Attributes
- Action Attributes
ABAC Diagram
User
│
Department = Finance
│
Location = Texas
│
Time = Business Hours
│
▼
Policy Evaluation
│
Access Granted
Example
Allow access only if:
- Department = Finance
- Country = USA
- Office Hours
- Resource Owner = User
Q3. What is the difference between RBAC and ABAC?
Answer
| RBAC | ABAC |
|---|---|
| Role-Based | Attribute-Based |
| Simple | Flexible |
| Static Permissions | Dynamic Policies |
| Easy Maintenance | More Complex |
| Limited Granularity | Fine-Grained Access |
| Best for Enterprise Apps | Best for Banking & Healthcare |
Interview Tip
RBAC answers:
What role does the user have?
ABAC answers:
Does the user satisfy all policy conditions?
Q4. How does RBAC work?
Answer
Users are assigned one or more roles.
Roles contain permissions.
Flow
User
↓
Role
↓
Permission
↓
Access Decision
Example
John
↓
ADMIN
↓
DELETE_USER
↓
Allowed
RBAC is simple because permissions are managed through roles.
Q5. How does ABAC work?
Answer
ABAC evaluates multiple attributes before granting access.
Flow
User Attributes
│
Resource Attributes
│
Environment Attributes
│
Action
│
Policy Engine
│
Access Granted / Denied
Example
Department = HR
AND
Country = USA
AND
Office Hours
↓
Allow Access
Q6. When should RBAC be used?
Answer
RBAC is suitable for applications with clearly defined roles.
Examples include:
- Banking Applications
- ERP Systems
- HR Applications
- E-Commerce Admin Portals
- University Systems
Example
Customer
↓
View Orders
-----------------
Admin
↓
Manage Products
Benefits
- Easy Administration
- Fast Authorization
- Easy Auditing
Q7. When should ABAC be used?
Answer
ABAC is suitable when access depends on business rules rather than fixed roles.
Examples include:
- Healthcare Systems
- Government Applications
- Insurance Platforms
- Banking
- Cloud Platforms
Example
Doctor
↓
Assigned Patient
↓
Hospital = Dallas
↓
Working Hours
↓
Access Medical Record
This level of control cannot be achieved easily using RBAC alone.
Q8. What are the advantages and disadvantages of RBAC and ABAC?
Answer
RBAC Advantages
- Simple
- Easy to manage
- Faster authorization
- Easy auditing
RBAC Disadvantages
- Role explosion
- Limited flexibility
- Difficult for dynamic policies
ABAC Advantages
- Fine-grained access
- Dynamic authorization
- Highly flexible
- Policy driven
ABAC Disadvantages
- Complex implementation
- Complex testing
- Difficult debugging
- Higher maintenance
Q9. Can RBAC and ABAC be used together?
Answer
Yes.
Most enterprise systems combine both models.
Hybrid Authorization
Authentication
↓
RBAC
↓
ABAC Policy Check
↓
Business Validation
↓
Access Granted
Production Example
Role = Manager
AND
Department = Finance
AND
Branch = Dallas
↓
Approve Loan
This approach provides both simplicity and flexibility.
Q10. What are the enterprise best practices for authorization?
Answer
Follow these best practices:
- Start with RBAC.
- Add ABAC for complex business rules.
- Apply Least Privilege.
- Validate authorization on every request.
- Use centralized policy management.
- Log authorization failures.
- Protect sensitive resources.
- Avoid hardcoded permissions.
- Review roles periodically.
- Implement backend authorization checks.
Enterprise Authorization Architecture
User
│
Authentication
│
JWT Validation
│
Spring Security
│
Role Verification (RBAC)
│
Policy Evaluation (ABAC)
│
Business Authorization
│
Business Services
│
Database
Senior Interview Tip
Most enterprise applications do not choose RBAC or ABAC exclusively.
A common approach is:
- RBAC for coarse-grained access (Admin, Manager, Customer)
- ABAC for fine-grained business rules (department, location, ownership, time, risk level)
This hybrid model offers the scalability of RBAC and the flexibility of ABAC, making it the preferred choice for modern enterprise applications.
Quick Revision
- RBAC is Role-Based Access Control.
- ABAC is Attribute-Based Access Control.
- RBAC is simple and role-centric.
- ABAC is dynamic and policy-driven.
- RBAC is suitable for most enterprise applications.
- ABAC is ideal for complex business rules.
- RBAC is easier to maintain.
- ABAC provides fine-grained authorization.
- Many organizations use a hybrid RBAC + ABAC approach.
- Always enforce authorization on the backend.