ISC2 CC Access Controls Concepts Practice Question
A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?
⚠ Common exam trap
The trap is that multiple options are 'access controls,' so candidates must match the control to the specific threat — unattended workstation — rather than picking a generally strong control like biometrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session timeout
A session timeout automatically locks or logs out a user after a period of inactivity, directly addressing the risk of an unattended workstation being used by an unauthorized person. It is the standard control for this scenario because it terminates the authenticated session without requiring the user to manually log off. Password complexity, biometrics, and account lockout address different threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password complexity
Why it's wrong here
Password complexity governs credential strength at authentication, not session state, so an unattended logged-in workstation remains accessible. It is tempting because complexity hardens accounts against brute-force and credential-guessing attacks, which is the right control when the risk is weak or reused passwords rather than physical exposure of an active session.
- ✗
Biometric authentication
Why it's wrong here
Biometric authentication verifies identity only at the initial logon event; it does not terminate or lock an existing session when the user walks away. It is tempting because biometrics resist credential sharing and replay, making it the right choice where the risk is impersonation at authentication rather than an unattended, already-authenticated workstation.
- ✓
Session timeout
Why this is correct
Session timeout automatically locks or terminates an idle session after a defined inactivity period, so an unattended workstation cannot be used by an unauthorised person. It directly addresses the walk-away threat rather than authentication or authorisation at logon.
- ✗
Account lockout
Why it's wrong here
Account lockout triggers on repeated failed authentication attempts, so it never fires when someone simply uses an already-authenticated session at an unattended workstation. It is tempting because lockout effectively blunts brute-force and password-spraying attacks, which is the correct control when the threat is repeated credential guessing rather than physical session exposure.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.