Courseiva
Access Controls Concepts →hardMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?

⚠ Common exam trap

The trap here is assuming that any label-based or fine-grained scheme is attribute-based access control, when rigid label and clearance enforcement is specifically mandatory access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandatory access control (MAC)

Mandatory access control bases decisions on labels attached to objects and clearances assigned to subjects, with enforcement handled by the system rather than by user discretion. The scenario's classification labels, clearance levels, and prohibition on bypassing checks all align with MAC. This model is typical in government and military settings where data sensitivity demands strict, non-discretionary control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-based access control (RBAC)

    Why it's wrong here

    RBAC ties permissions to job roles and is common in commercial environments. The scenario centers on classification labels and clearances enforced regardless of user preference, which is not how RBAC operates. Because access is governed by label comparison rather than role membership, role-based access control does not describe this environment.

  • ✓

    Mandatory access control (MAC)

    Why this is correct

    MAC enforces access based on sensitivity labels assigned to objects and clearances held by subjects, with the system, not users, controlling label changes. The scenario's classification labels, clearances, and inability to bypass checks are defining traits of MAC, making this the correct model.

  • ✗

    Discretionary access control (DAC)

    Why it's wrong here

    DAC allows resource owners to set permissions at their discretion, typically through access control lists. The scenario explicitly states that no user, including administrators, can change labels or bypass checks, which contradicts owner discretion. Therefore discretionary access control is not the model in use.

  • ✗

    Attribute-based access control (ABAC)

    Why it's wrong here

    ABAC evaluates multiple attributes such as department, time, and location through policies, offering fine-grained and flexible decisions. The scenario describes rigid label and clearance comparisons that even administrators cannot override, which is more restrictive and label-centric than typical ABAC. Thus attribute-based access control is not the best description here.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.