Courseiva
Access Controls Concepts →mediumMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A security team is reviewing how access control is enforced across a corporate environment. Which two statements accurately describe the relationship between identification, authentication, and authorization? (Choose two.)

⚠ Common exam trap

The trap here is treating authentication and authorization as interchangeable, when one verifies identity and the other determines permitted actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization decisions are made after authentication succeeds, based on the verified identity's permissions.

Identification claims an identity, authentication verifies that claim, and authorization grants permissions based on the verified identity. The two correct statements capture these distinct roles and their proper sequence. The remaining statements incorrectly merge authentication with authorization, allow authorization without authentication, or treat identification as sufficient for access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authorization decisions are made after authentication succeeds, based on the verified identity's permissions.

    Why this is correct

    Authorization determines what a verified identity may do, and it depends on knowing who the user is, which requires successful authentication first. Granting permissions before verifying identity would allow impersonation. This statement correctly reflects that authorization follows authentication and relies on the resulting identity context.

  • ✓

    Identification asserts an identity, while authentication verifies that the asserted identity is genuine.

    Why this is correct

    Identification is the claim of an identity, such as entering a username, and authentication validates that claim using credentials like a password, token, or biometric. These are distinct steps, and verification cannot occur before the identity is asserted. This statement accurately captures the sequence and meaning of the two concepts as applied in typical access control workflows.

  • ✗

    Identification alone is sufficient to grant access to protected resources in a secure system.

    Why it's wrong here

    Identification merely asserts an identity and does not prove it, so relying on it alone would let anyone claim another person's username and gain access. Secure systems require authentication to verify the claim before any authorization decision. This statement overstates the role of identification and would defeat the purpose of credential verification.

  • ✗

    A user can be authorized for a resource without ever being authenticated to the system.

    Why it's wrong here

    Authorization depends on a verified identity, so granting access without authentication would allow unidentified users to reach protected resources. While some systems use anonymous or guest access, that is a deliberate policy exception rather than the normal relationship between the two concepts. This statement misrepresents how authorization is normally tied to authentication.

  • ✗

    Authentication and authorization are the same process because both determine whether a user may access a resource.

    Why it's wrong here

    Authentication verifies who a user is, while authorization determines what that user may do. Treating them as the same process would blur the distinction between proving identity and granting permissions, which are separate steps with different mechanisms. This statement is inaccurate because it conflates verification of identity with the enforcement of access rights.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.