Be able to read a short scenario and name the principle or control category it demonstrates, and to separate identification from authentication. The single most important thing: know that authentication proves identity, while authorization decides what that proven identity may access.
Start practicing
Access Controls Concepts — choose a session length
Free · No account required
Domain overview
Domain 3 (Access Controls Concepts) covers how subjects are identified, authenticated, authorized, and held accountable for actions on assets. Expect scenario questions asking you to classify a control as preventive, detective, or corrective, to distinguish identification from authentication, and to match principles like least privilege, separation of duties, and need to know to short business situations.
Exam objectives
Distinguishing identification, authentication, authorization, and accountability in a given scenario
Applying least privilege, need to know, and separation of duties to described workflows
Classifying controls as administrative, technical, or physical and preventive, detective, or corrective
Recognizing authentication factors (something you know, have, are) and single sign-on concepts
Confusing identification with authentication: a username claims an identity, while a password, token, or biometric proves it.
Treating separation of duties and dual control as identical; dual control needs two people acting together, separation of duties splits a task across people.
Assuming role-based access control is the same as mandatory access control; RBAC uses job roles, MAC uses system-assigned labels.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?
2A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?
3An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?
4Which of the following is an example of a logical access control?
5According to NIST SP 800-63, which password policy is most recommended?
6What is the process of claiming an identity called?
7An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?
8A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?
9An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?
10Which of the following is a recommended practice for administrative accounts?
11A security administrator is configuring a session timeout policy. Which of the following are valid reasons for implementing session timeouts? (Choose TWO.)
12An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)
13A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)
14Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?
15A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?
16A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?
17Which of the following is a recommended practice for password security according to NIST SP 800-63?
18A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?
19What is the difference between identification and authentication?
20A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?
21An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?
22Which type of access control is implemented by a cable lock attached to a laptop?
23A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)
24Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)
25A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?
26A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?
27An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?
28According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?
29An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?
30In the context of identification and authentication, which of the following is an example of authentication?
31Which of the following best describes the purpose of a session timeout?
32A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?
33An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?
34A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?
35A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)
36An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)
37A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?
38An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?
39A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?
40An account lockout policy is implemented to protect against which type of attack?
41In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?
42Which process involves verifying the identity of a user who claims to be a specific person?
43An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?
44What is the primary purpose of a Privileged Access Management (PAM) solution?
45Which access control principle restricts access to data based on the user's job role and tasks?
46A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)
47An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)
48According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)
49Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?
50A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?
51A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:
52According to NIST SP 800-63, which password policy is recommended to enhance security?
53An account lockout policy is designed to mitigate which type of attack?
54A session timeout automatically logs out a user after a period of inactivity. This control primarily protects against:
55In the identification and authentication process, which step occurs first?
56An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?
57A Privileged Access Management (PAM) solution is used to:
58An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?
59A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?
60Which THREE are recommended practices for password policies according to current guidelines?
61An organization wants to implement defense in depth for its server room. Which THREE controls should be included?
62A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?
63An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:
64A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?
65A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?
66Which of the following is the primary purpose of a visitor log and escort policy?
67An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?
68In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?
69A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?
70An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?
71Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?
72An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:
73A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)
74Which THREE of the following are best practices for privileged account management? (Select THREE.)
75Which TWO of the following are components of the identification and authentication process? (Select TWO.)
76A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?
77An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?
78A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?
79A company's physical security includes fencing, security guards, access badges, and biometric locks on server room doors. This layered approach is an example of which access control concept?
80In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?
81An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?
82A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?
83An employee uses their username to claim an identity and then enters a password to prove it. What is the term for the process of proving the claimed identity?
84A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?
85In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?
86A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)
87Which TWO are examples of logical access controls? (Select TWO.)
88Which THREE are key components of Active Directory? (Select THREE.)
89A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)
90A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?
91A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?
92An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?
93A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?
94An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?
95A new employee at a marketing firm receives a company laptop, a proximity badge, and a one-time password token on their first day. Before being allowed to log in, the employee must enter their employee ID, then a code from the token, then scan the badge. Which access control concept does the employee ID represent in this sequence?
96A hospital's radiology department issues each technologist a smart card that must be inserted into a workstation reader before the technologist types a username and password. The smart card stores a digital certificate that the workstation validates. Which statement best describes how this arrangement maps to the identity and access control concepts?
97A hospital's IT team assigns each doctor a unique smart card that must be inserted before the workstation unlocks, and the card's embedded certificate is validated against the hospital's internal certificate authority. Which access control process does the smart card insertion and certificate validation represent?
98A payroll clerk changes roles within the same company, moving from the finance department to the human resources department. The security team discovers months later that the clerk still retains all the finance application permissions from the previous position in addition to the new HR permissions. Which access control weakness does this situation illustrate?
99A hospital's billing application assigns permissions based on each employee's job title, such as nurse, billing clerk, or department manager. When an employee changes roles, the administrator updates the job title and the application automatically adjusts the employee's access. Which access control model is being used?
100A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?
101A payroll clerk can view and edit employee salary records but cannot approve her own expense reimbursements, even though she processes reimbursements for other staff. Which access control principle does the restriction on approving her own reimbursements best illustrate?
102A financial services firm stores customer records in a database. A teller can read and update records for customers assigned to their branch but cannot view records belonging to other branches. A branch manager can view all records within their region. Which access control principle best explains why the teller's access is limited to their own branch's customers?
103A hospital's IT team wants to ensure that nurses can access patient records only during their assigned 12-hour shifts, even if their credentials are valid around the clock. Which access control model should the team implement to enforce this time-based restriction?
104A defense contractor classifies documents as Public, Internal, Secret, and Top Secret. A user with Secret clearance attempts to open a Top Secret document and is denied, while a user with Top Secret clearance can open both Top Secret and Secret documents. Which access control model does this behavior describe?
105A new employee logs in to the corporate network for the first time by entering a username and password. The system checks the credentials against the directory and grants access. Which security concept does entering the username and password represent?
106A hospital's IT team issues each nurse a unique smart card that is inserted into a workstation before the nurse types a password. The nurse then accesses patient records permitted for the assigned ward. Which combination of access control concepts is being demonstrated?
107A financial services firm grants a contractor temporary access to a trading application for a 90-day engagement. The security team wants the access to expire automatically without manual intervention, and also wants the contractor's manager to periodically confirm the access is still required. Which combination of access control practices best satisfies both requirements?
108A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?
109A user logs into a corporate portal by entering a username and password. The system then prompts for a one-time code from a mobile authenticator app. Which two factors of authentication are being combined in this scenario?
110A data center manager wants to strengthen physical access control at the main entrance while keeping the process practical for employees arriving each morning. Which two measures BEST align with sound physical access control practices? (Choose two.)
111A defense contractor classifies documents as Confidential, Secret, or Top Secret and requires that access decisions be based on these labels. Users receive clearances, and the system itself enforces that a user may read a document only if the user's clearance dominates the document's label. Users cannot change labels or grant access to others. Which access control model is being enforced?
112A security team is reviewing how access control is enforced across a corporate environment. Which two statements accurately describe the relationship between identification, authentication, and authorization? (Choose two.)
113A retail company is designing its access control program and wants to rely on attributes such as the user's department, the sensitivity label of the data, and the current time of day to make access decisions. Which TWO of the following statements accurately describe attribute-based access control (ABAC)? (Choose two.)
114A financial services firm must enforce access decisions based on data sensitivity labels assigned by a central authority, and users cannot change these labels or grant access to others. Which access control model is the firm implementing?
115A financial services firm grants tellers access to the transaction system only between 8:00 a.m. and 6:00 p.m. on business days, regardless of the teller's role. Access requests outside that window are automatically denied, and the restriction is enforced by a centrally managed policy that tellers cannot modify. Which access control approach is being applied?
116A hospital IT team is reviewing how staff access patient records. A nurse logs in with a unique employee ID, then enters a password plus a one-time code from a hardware token. The team wants to document which access control category this login process represents. Which category BEST describes this approach?
117A financial services firm is deploying a new customer portal. Auditors have required that access decisions consider the user's department, the data classification of the record, the time of day, and whether the request originates from a managed corporate device. The security architect proposes Attribute-Based Access Control (ABAC). Which two statements correctly describe how ABAC satisfies these requirements? (Choose two.)
118A security analyst is reviewing an access control list on a file server and notices that a former employee's account still has read and write permissions, even though the account was disabled three months ago. Which access control practice failed in this situation?
119A small design studio stores client files on a shared server. Each project folder is owned by the designer who created it, and that designer decides which colleagues may open the folder by granting permissions directly to individual accounts. Which access control model is the studio using?
120A financial services firm assigns permissions based on each employee's role in the HR system. When an employee transfers from accounting to marketing, the HR record changes and the employee's access is automatically updated to match the marketing role. Which access control model is the firm using?
121A hospital's data center uses a mantrap at its main entrance. A nurse badges in at the outer door, steps into a small glass vestibule, and the outer door locks before the inner door unlocks. What security goal does this design primarily achieve?
122A retail company issues managers a hardware token that generates a one-time code, which they enter after their password when signing in to the payroll system. A help desk technician asks why the company does not simply require longer passwords instead. Which statement best explains the security benefit of the token?
123A small marketing firm wants to give each employee a single set of credentials that works for the corporate email system, the cloud CRM, and the internal file share. The IT manager proposes using a central identity store so users do not have to remember separate passwords. Which concept is the IT manager describing?
124A security team is designing a physical access control system for a data center. They want to implement controls that verify a person's identity based on unique biological characteristics. Which two of the following are examples of biometric access controls? (Choose two.)
125A software company uses a central identity provider so employees can sign in once and access email, the code repository, and the expense system without entering credentials again during the workday. The security team wants to describe the mechanism that lets the identity provider assert the user's identity to each application. Which technology is being used?
126A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?
127A hospital's IT security team reviews how nurses access patient records. They find that a nurse who works in the cardiology unit can also open records for the oncology unit, even though the nurse never treats those patients. The team wants access decisions to be based on the department a nurse is assigned to plus the specific treatment relationship. Which access control model should they implement?
128A hospital issues each nurse a unique username and a badge that is scanned at a workstation to prove the nurse's identity before any patient records can be opened. Which access control concept does scanning the badge to prove identity represent?
129A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)
130A hospital's IT department issues every nurse a unique smart card that must be inserted into a workstation before the nurse types a password. The smart card alone does not grant access to patient records. Which access control concept does the smart card insertion represent?
131A retail company is reviewing physical access controls at its data center. Management wants to document measures that restrict who can enter the server hall and record when entries occur. Which TWO of the following are physical access controls that meet these goals? (Choose two.)
132A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?
133A security analyst reviews server logs and sees that a single service account performed a login from an office workstation at 09:00 and then, two minutes later, executed administrative commands from an external IP address in another country. The account's password is long and complex. Which access control weakness does this pattern most likely indicate?
134A small accounting firm wants to grant access to its tax software based on the department a user belongs to, rather than assigning permissions to each person individually. Which access control model should the firm implement to meet this requirement?
135A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?
136A security analyst notices that an employee who transferred from Finance to Marketing still has full access to financial reporting systems six months later. The analyst wants to correct this through the access control lifecycle. Which action best addresses the root cause?
137A retail chain wants store managers to approve refunds above $500, but the managers should not be able to approve their own refund transactions. The security team must enforce this separation in the point-of-sale system. Which access control model best fits this requirement?
138A software company allows developers to access production servers only during an approved change window, and only after a manager approves a request that includes a ticket number and expiration time. Access is automatically revoked when the window closes. Which access control approach is being used?
139A defense contractor classifies documents as Confidential, Secret, or Top Secret and assigns each employee a clearance level. Access is permitted only when the employee's clearance meets or exceeds the document's classification, and users cannot change these labels. Which access control model is in use?
140A security analyst is reviewing how a centralized authentication protocol validates user credentials before granting access to network resources. Which two characteristics correctly describe Kerberos authentication as used in a Windows domain environment? (Choose two.)
141A financial services firm classifies documents as Public, Internal, Confidential, and Restricted. Access to Restricted documents is determined solely by the document's classification label and the user's clearance level, and users cannot change either value. Which statement best describes this arrangement?
142A retail company issues contract workers temporary accounts that automatically expire after 30 days, and it reviews all active accounts each quarter to remove those no longer needed. Which access control administration practice does the quarterly review represent?
143A defense contractor runs a facility where entry to the secure lab requires a fingerprint scan, and entry to the adjacent server cage additionally requires a retina scan. A security analyst is documenting the access control design for an audit. Which two statements accurately describe these controls? (Choose two.)
144A software company wants contractors to access an internal code repository only during their contracted hours and only from company-managed laptops. The repository administrator should implement which type of access control to meet these conditions?
145A financial services firm is designing controls to enforce separation of duties in its payment approval process. Which two practices support this goal? (Choose two.)
146A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?
Be able to read a short scenario and name the principle or control category it demonstrates, and to separate identification from authentication. The single most important thing: know that authentication proves identity, while authorization decides what that proven identity may access.
The Courseiva CC question bank contains 146 questions in the Access Controls Concepts domain, covering the 22% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Access Controls Concepts domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included