20+ practice questions focused on Access Controls — one of the most tested topics on the Systems Security Certified Practitioner SSCP exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Access Controls PracticeA security engineer is designing a system that must ensure data integrity at all costs, even if it means sacrificing availability. Which access control model and corresponding principle should be applied?
Explanation: The Biba integrity model is specifically designed to protect data integrity by enforcing the 'no write-up' and 'no read-down' rules. 'No write-up' prevents subjects from writing to objects at a higher integrity level, stopping contamination of more trusted data. 'No read-down' prevents subjects from reading lower-integrity data, which could corrupt their own integrity and subsequently affect higher-level objects. Together, these rules ensure that integrity is preserved at all costs, even if it restricts availability (e.g., users cannot access lower-integrity data).
An organization is planning to implement a Single Sign-On (SSO) solution. Which THREE of the following are commonly associated with SSO technologies?
Explanation: Kerberos (A) is a classic SSO authentication protocol that uses a Key Distribution Center (KDC) to issue Ticket Granting Tickets (TGTs), allowing users to authenticate once and access multiple services without re-entering credentials. OAuth 2.0 (D) is an authorization framework commonly used for SSO, enabling an application to obtain delegated access tokens (e.g., via Authorization Code flow) so users can sign in through a trusted identity provider. SAML (E) is an XML-based federation standard widely used for browser-based SSO, where an Identity Provider issues signed assertions to a Service Provider to authenticate the user. Biometrics (B) is an authentication factor (something you are) rather than an SSO technology, and PKI (C) provides certificates and key management for identity and encryption but is not itself an SSO mechanism, though it can support one.
A security auditor is reviewing the account lifecycle process. Which TWO of the following are mandatory steps during the deprovisioning (offboarding) process?
Explanation: Option C is correct because immediately disabling the account is a mandatory first step in deprovisioning: it revokes the user's ability to authenticate and access resources right away, preventing any further unauthorized activity while the rest of the offboarding process is completed. Option A is correct because preserving evidence (such as mailbox contents, logs, and file access records) is required during offboarding so that any potential investigation, legal hold, or forensic review can proceed; destroying data prematurely could violate retention or e-discovery obligations. Option B is not appropriate because setting a default password leaves the account usable and creates a known credential that could be exploited; accounts should be disabled rather than given a predictable password. Option D is not mandatory because notification to the departing user is a courtesy/HR step, not a security control, and in hostile terminations notification may be deliberately withheld. Option E is not mandatory because immediately deleting the account and all associated data can destroy evidence and break retention requirements; disabling and later deleting after retention periods is the correct approach.
Which authentication method uses a time-based one-time password (TOTP) generated by a hardware or software token?
Explanation: TOTP (Time-based One-Time Password) is defined in RFC 6238 and generates codes based on the current time. It is commonly used with authenticator apps or hardware tokens.
An organization implements RBAC to enforce separation of duties. Which of the following is a key benefit of using role-based access control in this context?
Explanation: RBAC enforces separation of duties by assigning permissions to roles rather than individuals, and by preventing users from being assigned to conflicting roles. This reduces the risk of fraud because no single user has excessive privileges that could be abused. The key benefit is that it enforces least privilege and prevents toxic combinations of access.
+15 more Access Controls questions available
Practice all Access Controls questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Access Controls. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Access Controls questions on the SSCP frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Access Controls is tested as part of the Systems Security Certified Practitioner SSCP blueprint. Practicing with targeted Access Controls questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SSCP practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Access Controls is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Access Controls practice session with instant scoring and detailed explanations.
Start Access Controls Practice →