ISC2 CC Access Controls Concepts Practice Question
A small design studio stores client files on a shared server. Each project folder is owned by the designer who created it, and that designer decides which colleagues may open the folder by granting permissions directly to individual accounts. Which access control model is the studio using?
⚠ Common exam trap
The trap here is assuming that permissions granted to individual accounts automatically mean role-based access control, when the deciding factor is who holds the authority to grant them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Discretionary access control
Discretionary access control is defined by owner discretion: the person who owns a resource decides who else may use it. Each designer owns their project folder and personally grants permissions to individual colleagues, so the access decision rests with the owner rather than with central labels, roles, or global rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control
Why it's wrong here
Role-based access control grants permissions to roles rather than to named individuals, and users receive access by being assigned roles. Here permissions are handed directly to individual colleague accounts by the folder owner, with no role layer in between. The absence of role assignments means this is not role-based access control, even though the outcome may look similar to an observer.
- ✓
Discretionary access control
Why this is correct
Discretionary access control places the decision with the resource owner, who may grant or revoke access at their discretion. Because each designer owns the project folder and personally decides which colleagues can open it by assigning permissions to individual accounts, the model matches discretionary access control exactly. The owner's judgment, not a central policy, determines who gets in.
- ✗
Rule-based access control
Why it's wrong here
Rule-based access control applies global rules that are not tied to individual resource ownership, such as firewall rules or time-of-day restrictions. In this scenario there is no global rule engine making decisions; a specific person decides who may open a specific folder. The owner-driven nature of the decision points to discretionary access control rather than a rule-based mechanism.
- ✗
Mandatory access control
Why it's wrong here
Mandatory access control relies on system-enforced labels and clearances that users cannot change. In this studio, the designer freely chooses who may access the folder, which means the owner controls the decision rather than a central label policy. That owner discretion is the opposite of the mandatory model, where even the resource owner cannot override the label comparison performed by the system.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.