Capability table
A list bound to a subject that records every object it may access and the rights it holds over each; one row of the access control matrix, and the counterpart to an access control list.
A capability table (or capability list) is held with a subject rather than with an object. It lists each object the subject may reach and the rights it has over each. In terms of the access control matrix, it is one row: one subject, every object. The column view of the same matrix is the access control list.
Each entry is a capability, a token that names an object and a set of rights. In capability-based systems, presenting a valid capability is enough to gain the access it names, so capabilities must be protected against forgery and tampering, commonly by keeping them in memory the subject cannot alter or by protecting them cryptographically. Listing everything a user can reach, and delegating a right by passing a capability on, are straightforward. Revoking a right from one object is harder, because the capabilities that grant it are held by the subjects, wherever they are. An access control list has the opposite profile.
Exam relevance: questions in this area tend to turn on orientation. Candidates are expected to link capability tables to subjects and matrix rows, access control lists to objects and matrix columns, and to know which of the two makes revocation easier.