ISC2 CC Access Controls Concepts Practice Question
A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)
⚠ Common exam trap
The trap here is conflating authentication with authorization, assuming that a verified login automatically prevents actions the user should not perform.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization determines what an authenticated cashier is permitted to do within the point-of-sale application.
Authorization defines what an authenticated identity may do, and least privilege limits that access to what the job requires. Together they support the proposed point-of-sale restrictions on voids and inventory adjustments. Authentication merely establishes identity, while role-based access control assigns permissions through roles rather than individual assignments, and password complexity addresses authentication strength only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization determines what an authenticated cashier is permitted to do within the point-of-sale application.
Why this is correct
Authorization occurs after authentication and defines the resources and actions available to an identity. Restricting voids above a threshold and limiting inventory adjustments are authorization decisions applied to an authenticated cashier. This statement correctly describes authorization as the mechanism enforcing these granular permissions in the point-of-sale design.
- ✗
Authentication alone ensures that a cashier cannot perform unauthorized transactions.
Why it's wrong here
Authentication only verifies the identity of the cashier; it does not constrain what that identity may do. Without authorization rules, an authenticated cashier could attempt any function the application exposes. This statement is incorrect because authentication and authorization are separate functions, and authentication by itself does not prevent unauthorized transactions.
- ✓
Least privilege supports limiting each cashier to only the point-of-sale functions required for the assigned duties.
Why this is correct
Least privilege means granting only the minimum access necessary to perform job duties. Applying it to cashiers would restrict functions like high-value voids or inventory changes unless specifically required. This statement correctly connects the principle to the proposed point-of-sale restrictions and supports the architect's design.
- ✗
Access control decisions should be based solely on the cashier's password complexity.
Why it's wrong here
Password complexity affects the strength of authentication but does not determine authorization or permissible actions. Basing access decisions solely on password complexity would ignore roles, least privilege, and business rules. This statement is incorrect because access control decisions depend on identity, role, and policy, not merely on how complex a password is.
- ✗
Role-based access control requires each cashier to be assigned permissions individually rather than through a shared role.
Why it's wrong here
RBAC deliberately assigns permissions to roles and then assigns users to those roles, avoiding individual permission management. Stating that RBAC requires per-user permission assignment contradicts the model's core purpose. This statement is incorrect because it reverses how role-based access control actually operates in the described retail environment.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.