ISC2 CC Access Controls Concepts Practice Question
A retail company is designing its access control program and wants to rely on attributes such as the user's department, the sensitivity label of the data, and the current time of day to make access decisions. Which TWO of the following statements accurately describe attribute-based access control (ABAC)? (Choose two.)
⚠ Common exam trap
The trap here is assuming ABAC is just role-based access control with a different name, when its defining feature is evaluating many dynamic attributes at request time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ABAC can enforce rules such as permitting access only during business hours from a corporate network.
ABAC makes decisions by evaluating attributes of the subject, resource, action, and environment, which enables granular rules such as time-limited and location-aware access. It does not depend on a single job title, does not require one fixed role per user, and can absolutely incorporate data sensitivity labels as resource attributes. The two accurate statements describe multi-attribute evaluation and environmental conditions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ABAC requires that every user be assigned exactly one static role that never changes.
Why it's wrong here
Static single-role assignment describes a rigid role-based model, not ABAC. ABAC is dynamic and policy-driven, evaluating attributes at request time so the outcome can differ for the same user depending on resource and environment. Requiring exactly one unchanging role would contradict the flexibility that makes attribute-based decisions valuable in the first place.
- ✓
ABAC can enforce rules such as permitting access only during business hours from a corporate network.
Why this is correct
Environmental attributes such as time of day and network location are first-class inputs in ABAC policy evaluation. A rule that grants access only between 08:00 and 18:00 when the request originates from the corporate network is a classic environmental condition. This illustrates how ABAC extends beyond identity alone to consider the context in which the access request occurs.
- ✓
ABAC evaluates policies using attributes of the subject, the resource, the action, and the environment.
Why this is correct
ABAC policies are expressed in terms of attributes drawn from multiple sources: subject attributes like department or clearance, resource attributes like data classification, action attributes like read or write, and environmental attributes like time or location. This multi-attribute evaluation is the defining characteristic of ABAC and allows far more granular rules than static role assignments alone can express.
- ✗
ABAC policies cannot incorporate data sensitivity labels because labels are a form of mandatory access control.
Why it's wrong here
Sensitivity labels are simply resource attributes and are entirely compatible with ABAC. While label-based comparison is central to mandatory access control, ABAC can consume the same labels as one input among many. Claiming the two are mutually exclusive misstates how ABAC policies are written, since resource classification is one of the most common attributes used in practice.
- ✗
ABAC decisions are made solely from the user's job title stored in the human resources system.
Why it's wrong here
Using only a job title would be a narrow, role-centric approach rather than true ABAC. ABAC deliberately combines many attributes, including resource classification and environmental context, so a decision never rests on a single subject attribute. Restricting evaluation to job title would ignore the sensitivity of the data and conditions like time of day, defeating the purpose of the attribute-rich model.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.