Courseiva
Access Controls Concepts →hardMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?

⚠ Common exam trap

The trap here is selecting rule-based access control because branch protection sounds like a rule, when the scenario is really about permissions assigned by job function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-based access control (RBAC), because permissions are tied to job functions like developer and release manager

Role-based access control defines permissions for roles and assigns users to those roles, so developers and the release manager receive exactly the rights their job functions require. Because the rules are centrally defined rather than owner-controlled, they are enforced consistently. Discretionary control would leave decisions to owners, mandatory control relies on labels, and rule-based control evaluates environmental conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Discretionary access control (DAC), because repository owners can set permissions as they see fit

    Why it's wrong here

    Discretionary access control lets resource owners decide who gets access, which would allow a repository owner to grant tag creation rights to anyone. The company wants rules enforced consistently regardless of ownership, so relying on owner discretion would undermine the requirement. DAC cannot guarantee the fixed separation described between developers and the release manager.

  • ✗

    Mandatory access control (MAC), because labels and clearances prevent unauthorized modifications

    Why it's wrong here

    Mandatory access control uses sensitivity labels and clearance levels assigned by a central authority, and access is determined by label comparisons. The scenario does not involve classified data, labels, or clearances, and the company's rules are about job functions rather than data sensitivity. MAC would be unnecessarily rigid and does not map to the developer and release manager distinction.

  • ✗

    Rule-based access control, because conditions such as branch protection rules can restrict actions

    Why it's wrong here

    Rule-based access control evaluates explicit conditions, such as time, location, or network, to permit or deny access. While branch protection rules sound similar, they are policy conditions rather than an access control model driven by user attributes. The scenario is fundamentally about assigning permissions according to job roles, which points to a different model.

  • ✓

    Role-based access control (RBAC), because permissions are tied to job functions like developer and release manager

    Why this is correct

    RBAC assigns permissions to roles and users to roles, so developers receive read and commit rights while the release manager receives tag creation rights. Because the rules are defined centrally by role rather than by repository ownership, they apply consistently to everyone. This matches the company's requirement that the separation be enforced regardless of who owns the repository.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.