Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?

⚠ Common exam trap

The trap is that multiple options are 'access controls,' so candidates must match the control to the specific threat — unattended workstation — rather than picking a generally strong control like biometrics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session timeout

A session timeout automatically locks or logs out a user after a period of inactivity, directly addressing the risk of an unattended workstation being used by an unauthorized person. It is the standard control for this scenario because it terminates the authenticated session without requiring the user to manually log off. Password complexity, biometrics, and account lockout address different threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password complexity

    Why it's wrong here

    Password complexity governs credential strength at authentication, not session state, so an unattended logged-in workstation remains accessible. It is tempting because complexity hardens accounts against brute-force and credential-guessing attacks, which is the right control when the risk is weak or reused passwords rather than physical exposure of an active session.

  • ✗

    Biometric authentication

    Why it's wrong here

    Biometric authentication verifies identity only at the initial logon event; it does not terminate or lock an existing session when the user walks away. It is tempting because biometrics resist credential sharing and replay, making it the right choice where the risk is impersonation at authentication rather than an unattended, already-authenticated workstation.

  • ✓

    Session timeout

    Why this is correct

    Session timeout automatically locks or terminates an idle session after a defined inactivity period, so an unattended workstation cannot be used by an unauthorised person. It directly addresses the walk-away threat rather than authentication or authorisation at logon.

  • ✗

    Account lockout

    Why it's wrong here

    Account lockout triggers on repeated failed authentication attempts, so it never fires when someone simply uses an already-authenticated session at an unattended workstation. It is tempting because lockout effectively blunts brute-force and password-spraying attacks, which is the correct control when the threat is repeated credential guessing rather than physical session exposure.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.