ISC2 CC Access Controls Concepts Practice Question
A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?
⚠ Common exam trap
The trap here is treating any centrally managed permission scheme as mandatory access control when the scenario actually describes role assignment without security labels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based access control (RBAC)
Assigning rights to roles and then placing users into those roles is the essence of role-based access control. The transfer scenario shows the key benefit: permissions follow the job function, so moving an employee between departments automatically strips old rights and applies new ones without editing each user's individual access list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Discretionary access control (DAC)
Why it's wrong here
In DAC, the owner of a resource decides who may access it and what rights they hold, which leads to inconsistent, owner-driven permissions. Here permissions flow from a centralized department assignment rather than from individual resource owners granting access. The automated removal and addition of rights based on job role is characteristic of a different model, so DAC does not fit this scenario.
- ✓
Role-based access control (RBAC)
Why this is correct
RBAC grants permissions to roles, and users receive rights by being assigned to a role. When the employee moves from the Teller role to the Loan Officer role, the old role's permissions drop away and the new role's permissions apply, exactly as described. This role-to-permission mapping with automatic reassignment is the defining behavior of role-based access control.
- ✗
Mandatory access control (MAC)
Why it's wrong here
MAC uses security labels and clearances assigned by a central authority, and users cannot change those labels; it is common in military and highly classified environments. This firm assigns rights by business department, not by sensitivity labels compared against clearance levels. Nothing in the scenario describes label-based enforcement, so MAC misrepresents how the permissions are actually derived.
- ✗
Rule-based access control
Why it's wrong here
Rule-based access control evaluates conditions such as time of day, source IP address, or location to decide access, often implemented in firewalls and routers. The scenario describes permissions tied to job functions and department membership, not conditional rules evaluated at request time. Because no dynamic condition is checked, rule-based access control does not explain the automated permission changes.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.