ISC2 CC Access Controls Concepts Practice Question
A new employee at a marketing firm receives a company laptop, a proximity badge, and a one-time password token on their first day. Before being allowed to log in, the employee must enter their employee ID, then a code from the token, then scan the badge. Which access control concept does the employee ID represent in this sequence?
⚠ Common exam trap
The trap here is assuming any credential entered during login is authentication, when the initial identifier entry is actually identification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identification
Identification is the claim of an identity, such as typing a username or employee ID, while authentication verifies that claim with credentials. In this scenario the employee ID is asserted before the token code and badge scan, so it functions as the identification step. Authorization and accounting occur only after identity is verified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accounting
Why it's wrong here
Accounting, or auditing, is the process of logging and reviewing user activity to support accountability and forensic investigation. It records what an authenticated user did, not who they claim to be. Entering an employee ID at the start of a login sequence is an identity claim, so accounting does not describe this step.
- ✗
Authorization
Why it's wrong here
Authorization determines what resources an authenticated identity is permitted to access, based on policies, roles, or permissions. It occurs after identity has been verified and does not involve entering an identifier. The employee ID entry happens before any verification or permission decision, so it cannot be the authorization step in this workflow.
- ✗
Authentication
Why it's wrong here
Authentication is the process of verifying a claimed identity by validating one or more credentials, such as a token code or a badge scan. Here the employee ID alone is simply asserted and not yet validated, so it does not perform verification. The token code and badge scan are the verifying factors in this scenario, which is why authentication is not the correct characterization of the employee ID entry.
- ✓
Identification
Why this is correct
Identification is the act of claiming an identity, typically by entering a username, employee ID, or similar identifier that the system can recognize. The employee ID is asserted first and then verified by the token and badge. Because the ID by itself only names who the person claims to be, it is the identification step in this access control sequence.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.