ISC2 CC Access Controls Concepts Practice Question
A new employee logs in to the corporate network for the first time by entering a username and password. The system checks the credentials against the directory and grants access. Which security concept does entering the username and password represent?
⚠ Common exam trap
The trap here is treating the username as the whole event and choosing identification, when the presence of a validated password makes the process authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication
When a user supplies a username and password and the system validates them against stored credentials, the system is verifying the claimed identity. That verification step is authentication. Identification alone is just the claim of an identity, and authorization and accounting happen after authentication succeeds, so authentication is the concept being exercised here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authentication
Why this is correct
Authentication is the process of verifying that a subject's claimed identity is genuine, typically by validating something the subject knows, has, or is. Entering a username and password and having the directory confirm them is the classic example of authentication. The system is proving the employee is who they claim to be before any access decision is made.
- ✗
Authorization
Why it's wrong here
Authorization determines what an authenticated subject is permitted to do, such as reading a file or running an application. In this scenario the employee has only supplied credentials and been validated; no permission decision about resources has been described. Authorization occurs after successful authentication, so it does not describe the act of presenting a username and password.
- ✗
Accounting
Why it's wrong here
Accounting, or auditing, is the process of recording and reviewing user activity so actions can be traced to an identity. The scenario describes a login validation step, not the logging or review of activity. While a successful login may generate an audit record, the core concept being exercised when credentials are checked is not accounting.
- ✗
Identification
Why it's wrong here
Identification is the act of claiming an identity, such as typing a username or presenting a badge. It is only the first half of the process; by itself it proves nothing because anyone could type another person's username. The scenario also includes the password being checked against the directory, which goes beyond mere identification and constitutes authentication.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.