Courseiva
Access Controls Concepts →hardMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A defense contractor classifies documents as Confidential, Secret, or Top Secret and requires that access decisions be based on these labels. Users receive clearances, and the system itself enforces that a user may read a document only if the user's clearance dominates the document's label. Users cannot change labels or grant access to others. Which access control model is being enforced?

⚠ Common exam trap

The trap here is focusing on the word 'clearance' and picking role-based control, when the decisive clue is that labels are system-enforced and users cannot delegate access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandatory Access Control (MAC)

The system bases every access decision on system-assigned classification labels and user clearances, and users cannot modify those labels or delegate access. That combination of non-discretionary, label-driven enforcement is Mandatory Access Control. The dominance rule described, where clearance must dominate the object label for read access, is a hallmark of mandatory models such as Bell-LaPadula.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-Based Access Control (RBAC)

    Why it's wrong here

    RBAC assigns permissions to roles and users to roles, which is useful for job-function administration but does not by itself compare clearance levels against object labels. The scenario centers on classification labels and clearances dominating one another, not on role membership. RBAC could complement such a system, but it is not the model enforcing the label comparison described.

  • ✓

    Mandatory Access Control (MAC)

    Why this is correct

    MAC enforces access decisions from system-controlled labels rather than from user discretion. Subjects receive clearances and objects receive classifications, and the system permits access only when the clearance dominates the label. Because users cannot alter labels or extend access to others, this precisely matches the described enforcement, including the dominance rule for reading.

  • ✗

    Discretionary Access Control (DAC)

    Why it's wrong here

    In DAC the owner of a resource decides who may access it, usually through access control lists, and owners can pass permissions to others. The scenario explicitly states that users cannot change labels or grant access to others, which contradicts the discretionary nature of DAC. Label-based, system-enforced decisions are the defining characteristic of mandatory models instead.

  • ✗

    Attribute-Based Access Control (ABAC)

    Why it's wrong here

    ABAC evaluates policies built from many attributes of subjects, objects, actions, and environment, which can be far more granular than simple labels. The scenario describes a strict label-and-clearance comparison with no mention of environmental or multi-attribute policy evaluation. While ABAC could theoretically model label rules, the described system is the classic mandatory label model rather than attribute-driven policy.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.