Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?

⚠ Common exam trap

The trap here is treating any centrally managed permission scheme as mandatory access control when the scenario actually describes role assignment without security labels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-based access control (RBAC)

Assigning rights to roles and then placing users into those roles is the essence of role-based access control. The transfer scenario shows the key benefit: permissions follow the job function, so moving an employee between departments automatically strips old rights and applies new ones without editing each user's individual access list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Discretionary access control (DAC)

    Why it's wrong here

    In DAC, the owner of a resource decides who may access it and what rights they hold, which leads to inconsistent, owner-driven permissions. Here permissions flow from a centralized department assignment rather than from individual resource owners granting access. The automated removal and addition of rights based on job role is characteristic of a different model, so DAC does not fit this scenario.

  • ✓

    Role-based access control (RBAC)

    Why this is correct

    RBAC grants permissions to roles, and users receive rights by being assigned to a role. When the employee moves from the Teller role to the Loan Officer role, the old role's permissions drop away and the new role's permissions apply, exactly as described. This role-to-permission mapping with automatic reassignment is the defining behavior of role-based access control.

  • ✗

    Mandatory access control (MAC)

    Why it's wrong here

    MAC uses security labels and clearances assigned by a central authority, and users cannot change those labels; it is common in military and highly classified environments. This firm assigns rights by business department, not by sensitivity labels compared against clearance levels. Nothing in the scenario describes label-based enforcement, so MAC misrepresents how the permissions are actually derived.

  • ✗

    Rule-based access control

    Why it's wrong here

    Rule-based access control evaluates conditions such as time of day, source IP address, or location to decide access, often implemented in firewalls and routers. The scenario describes permissions tied to job functions and department membership, not conditional rules evaluated at request time. Because no dynamic condition is checked, rule-based access control does not explain the automated permission changes.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.