Courseiva
Access Controls Concepts →hardMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)

⚠ Common exam trap

The trap here is conflating authentication with authorization, assuming that a verified login automatically prevents actions the user should not perform.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization determines what an authenticated cashier is permitted to do within the point-of-sale application.

Authorization defines what an authenticated identity may do, and least privilege limits that access to what the job requires. Together they support the proposed point-of-sale restrictions on voids and inventory adjustments. Authentication merely establishes identity, while role-based access control assigns permissions through roles rather than individual assignments, and password complexity addresses authentication strength only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authorization determines what an authenticated cashier is permitted to do within the point-of-sale application.

    Why this is correct

    Authorization occurs after authentication and defines the resources and actions available to an identity. Restricting voids above a threshold and limiting inventory adjustments are authorization decisions applied to an authenticated cashier. This statement correctly describes authorization as the mechanism enforcing these granular permissions in the point-of-sale design.

  • ✗

    Authentication alone ensures that a cashier cannot perform unauthorized transactions.

    Why it's wrong here

    Authentication only verifies the identity of the cashier; it does not constrain what that identity may do. Without authorization rules, an authenticated cashier could attempt any function the application exposes. This statement is incorrect because authentication and authorization are separate functions, and authentication by itself does not prevent unauthorized transactions.

  • ✓

    Least privilege supports limiting each cashier to only the point-of-sale functions required for the assigned duties.

    Why this is correct

    Least privilege means granting only the minimum access necessary to perform job duties. Applying it to cashiers would restrict functions like high-value voids or inventory changes unless specifically required. This statement correctly connects the principle to the proposed point-of-sale restrictions and supports the architect's design.

  • ✗

    Access control decisions should be based solely on the cashier's password complexity.

    Why it's wrong here

    Password complexity affects the strength of authentication but does not determine authorization or permissible actions. Basing access decisions solely on password complexity would ignore roles, least privilege, and business rules. This statement is incorrect because access control decisions depend on identity, role, and policy, not merely on how complex a password is.

  • ✗

    Role-based access control requires each cashier to be assigned permissions individually rather than through a shared role.

    Why it's wrong here

    RBAC deliberately assigns permissions to roles and then assigns users to those roles, avoiding individual permission management. Stating that RBAC requires per-user permission assignment contradicts the model's core purpose. This statement is incorrect because it reverses how role-based access control actually operates in the described retail environment.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.