ISC2 CC Access Controls Concepts Practice Question
A hospital's billing application assigns permissions based on each employee's job title, such as nurse, billing clerk, or department manager. When an employee changes roles, the administrator updates the job title and the application automatically adjusts the employee's access. Which access control model is being used?
⚠ Common exam trap
A common mix-up: candidates confuse role-based access control with rule-based access control because both can be automated, but only RBAC ties permissions to a job function or role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based access control (RBAC)
Role-based access control assigns permissions to roles and then assigns users to those roles, so access changes automatically when a user's role changes. The hospital's job-title-driven permissions match this model. Discretionary control lets owners set permissions, mandatory control uses labels and clearances, and rule-based control evaluates conditions rather than job functions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mandatory access control (MAC)
Why it's wrong here
Mandatory access control relies on security labels and clearances assigned by a central authority, and users cannot change those labels. The scenario does not mention classification labels, sensitivity levels, or clearance comparisons. Permissions here follow job titles rather than label dominance rules, so MAC is not the model in use.
- ✗
Rule-based access control
Why it's wrong here
Rule-based access control evaluates explicit conditions, such as time of day, source IP address, or location, to decide access. The hospital application is not making decisions based on environmental conditions but on the employee's assigned job function. Since permissions are tied to roles rather than conditional rules, this model does not describe the scenario.
- ✗
Discretionary access control (DAC)
Why it's wrong here
In discretionary access control, the owner of a resource decides who may access it and with what permissions, which gives users broad discretion over sharing. This hospital application instead derives permissions from centrally defined job titles, not from resource owners making individual sharing decisions. The automated role-based adjustment described does not match the discretionary model.
- ✓
Role-based access control (RBAC)
Why this is correct
Role-based access control grants permissions to roles, and users receive permissions by being assigned to a role. In this scenario the job title acts as the role, and changing the title automatically changes access. This central administration of permissions through roles, rather than per-user grants, is the defining characteristic of RBAC.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.