ISC2 CC Access Controls Concepts Practice Question
A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?
⚠ Common exam trap
The trap here is assuming that any label-based or fine-grained scheme is attribute-based access control, when rigid label and clearance enforcement is specifically mandatory access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mandatory access control (MAC)
Mandatory access control bases decisions on labels attached to objects and clearances assigned to subjects, with enforcement handled by the system rather than by user discretion. The scenario's classification labels, clearance levels, and prohibition on bypassing checks all align with MAC. This model is typical in government and military settings where data sensitivity demands strict, non-discretionary control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control (RBAC)
Why it's wrong here
RBAC ties permissions to job roles and is common in commercial environments. The scenario centers on classification labels and clearances enforced regardless of user preference, which is not how RBAC operates. Because access is governed by label comparison rather than role membership, role-based access control does not describe this environment.
- ✓
Mandatory access control (MAC)
Why this is correct
MAC enforces access based on sensitivity labels assigned to objects and clearances held by subjects, with the system, not users, controlling label changes. The scenario's classification labels, clearances, and inability to bypass checks are defining traits of MAC, making this the correct model.
- ✗
Discretionary access control (DAC)
Why it's wrong here
DAC allows resource owners to set permissions at their discretion, typically through access control lists. The scenario explicitly states that no user, including administrators, can change labels or bypass checks, which contradicts owner discretion. Therefore discretionary access control is not the model in use.
- ✗
Attribute-based access control (ABAC)
Why it's wrong here
ABAC evaluates multiple attributes such as department, time, and location through policies, offering fine-grained and flexible decisions. The scenario describes rigid label and clearance comparisons that even administrators cannot override, which is more restrictive and label-centric than typical ABAC. Thus attribute-based access control is not the best description here.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.