Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?

⚠ Common exam trap

The trap here is assuming that any centralized or administrator-managed model automatically groups permissions by job function, when only RBAC assigns permissions to roles that users then occupy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-Based Access Control (RBAC)

The hospital needs permissions tied to job functions rather than to individual accounts. Role-Based Access Control creates roles, assigns permissions to those roles, and then assigns users to roles, so rotating staff only requires changing the role assignment. This reduces administrative errors, supports least privilege at the role level, and scales cleanly as departments and duties change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Discretionary Access Control (DAC)

    Why it's wrong here

    DAC lets the owner of a resource decide who can access it, typically through access control lists. While flexible, it keeps permission decisions distributed among data owners and does not provide the centralized, job-function-based grouping the hospital needs. Assigning each nurse permissions individually is essentially what DAC encourages, which is the very problem the team wants to eliminate.

  • ✓

    Role-Based Access Control (RBAC)

    Why this is correct

    RBAC grants permissions to roles rather than to individual users, and users receive permissions by being assigned to a role. Creating a 'Pediatric Nurse' role and assigning nurses to it directly solves the rotation and administration problem described. When a nurse moves departments, only the role assignment changes, and permissions follow automatically, reducing errors.

  • ✗

    Mandatory Access Control (MAC)

    Why it's wrong here

    MAC bases access decisions on security labels assigned to subjects and objects, and only administrators can change those labels, not end users. The hospital's goal is to bundle permissions into job-based roles and assign staff to them, which is not what label-driven MAC provides. MAC would add heavy administrative overhead and does not address the role rotation problem described.

  • ✗

    Rule-Based Access Control

    Why it's wrong here

    Rule-based access control evaluates administrator-defined rules such as time-of-day or network-address conditions, often implemented on routers and firewalls. It does not organize permissions around job functions or roles, so it would not simplify assigning nurses to a 'Pediatric Nurse' permission set. The scenario requires identity-to-permission mapping by role, not conditional rules.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.