Courseiva
Access Controls Concepts →mediumMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A retail company is designing its access control program and wants to rely on attributes such as the user's department, the sensitivity label of the data, and the current time of day to make access decisions. Which TWO of the following statements accurately describe attribute-based access control (ABAC)? (Choose two.)

⚠ Common exam trap

The trap here is assuming ABAC is just role-based access control with a different name, when its defining feature is evaluating many dynamic attributes at request time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ABAC can enforce rules such as permitting access only during business hours from a corporate network.

ABAC makes decisions by evaluating attributes of the subject, resource, action, and environment, which enables granular rules such as time-limited and location-aware access. It does not depend on a single job title, does not require one fixed role per user, and can absolutely incorporate data sensitivity labels as resource attributes. The two accurate statements describe multi-attribute evaluation and environmental conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ABAC requires that every user be assigned exactly one static role that never changes.

    Why it's wrong here

    Static single-role assignment describes a rigid role-based model, not ABAC. ABAC is dynamic and policy-driven, evaluating attributes at request time so the outcome can differ for the same user depending on resource and environment. Requiring exactly one unchanging role would contradict the flexibility that makes attribute-based decisions valuable in the first place.

  • ✓

    ABAC can enforce rules such as permitting access only during business hours from a corporate network.

    Why this is correct

    Environmental attributes such as time of day and network location are first-class inputs in ABAC policy evaluation. A rule that grants access only between 08:00 and 18:00 when the request originates from the corporate network is a classic environmental condition. This illustrates how ABAC extends beyond identity alone to consider the context in which the access request occurs.

  • ✓

    ABAC evaluates policies using attributes of the subject, the resource, the action, and the environment.

    Why this is correct

    ABAC policies are expressed in terms of attributes drawn from multiple sources: subject attributes like department or clearance, resource attributes like data classification, action attributes like read or write, and environmental attributes like time or location. This multi-attribute evaluation is the defining characteristic of ABAC and allows far more granular rules than static role assignments alone can express.

  • ✗

    ABAC policies cannot incorporate data sensitivity labels because labels are a form of mandatory access control.

    Why it's wrong here

    Sensitivity labels are simply resource attributes and are entirely compatible with ABAC. While label-based comparison is central to mandatory access control, ABAC can consume the same labels as one input among many. Claiming the two are mutually exclusive misstates how ABAC policies are written, since resource classification is one of the most common attributes used in practice.

  • ✗

    ABAC decisions are made solely from the user's job title stored in the human resources system.

    Why it's wrong here

    Using only a job title would be a narrow, role-centric approach rather than true ABAC. ABAC deliberately combines many attributes, including resource classification and environmental context, so a decision never rests on a single subject attribute. Restricting evaluation to job title would ignore the sensitivity of the data and conditions like time of day, defeating the purpose of the attribute-rich model.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.