ISC2 CC Access Controls Concepts Practice Question
A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?
⚠ Common exam trap
The trap here is assuming that any centralized or administrator-managed model automatically groups permissions by job function, when only RBAC assigns permissions to roles that users then occupy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-Based Access Control (RBAC)
The hospital needs permissions tied to job functions rather than to individual accounts. Role-Based Access Control creates roles, assigns permissions to those roles, and then assigns users to roles, so rotating staff only requires changing the role assignment. This reduces administrative errors, supports least privilege at the role level, and scales cleanly as departments and duties change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Discretionary Access Control (DAC)
Why it's wrong here
DAC lets the owner of a resource decide who can access it, typically through access control lists. While flexible, it keeps permission decisions distributed among data owners and does not provide the centralized, job-function-based grouping the hospital needs. Assigning each nurse permissions individually is essentially what DAC encourages, which is the very problem the team wants to eliminate.
- ✓
Role-Based Access Control (RBAC)
Why this is correct
RBAC grants permissions to roles rather than to individual users, and users receive permissions by being assigned to a role. Creating a 'Pediatric Nurse' role and assigning nurses to it directly solves the rotation and administration problem described. When a nurse moves departments, only the role assignment changes, and permissions follow automatically, reducing errors.
- ✗
Mandatory Access Control (MAC)
Why it's wrong here
MAC bases access decisions on security labels assigned to subjects and objects, and only administrators can change those labels, not end users. The hospital's goal is to bundle permissions into job-based roles and assign staff to them, which is not what label-driven MAC provides. MAC would add heavy administrative overhead and does not address the role rotation problem described.
- ✗
Rule-Based Access Control
Why it's wrong here
Rule-based access control evaluates administrator-defined rules such as time-of-day or network-address conditions, often implemented on routers and firewalls. It does not organize permissions around job functions or roles, so it would not simplify assigning nurses to a 'Pediatric Nurse' permission set. The scenario requires identity-to-permission mapping by role, not conditional rules.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.