ISC2 CC Access Controls Concepts Practice Question
A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?
⚠ Common exam trap
The trap here is selecting rule-based access control because branch protection sounds like a rule, when the scenario is really about permissions assigned by job function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based access control (RBAC), because permissions are tied to job functions like developer and release manager
Role-based access control defines permissions for roles and assigns users to those roles, so developers and the release manager receive exactly the rights their job functions require. Because the rules are centrally defined rather than owner-controlled, they are enforced consistently. Discretionary control would leave decisions to owners, mandatory control relies on labels, and rule-based control evaluates environmental conditions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Discretionary access control (DAC), because repository owners can set permissions as they see fit
Why it's wrong here
Discretionary access control lets resource owners decide who gets access, which would allow a repository owner to grant tag creation rights to anyone. The company wants rules enforced consistently regardless of ownership, so relying on owner discretion would undermine the requirement. DAC cannot guarantee the fixed separation described between developers and the release manager.
- ✗
Mandatory access control (MAC), because labels and clearances prevent unauthorized modifications
Why it's wrong here
Mandatory access control uses sensitivity labels and clearance levels assigned by a central authority, and access is determined by label comparisons. The scenario does not involve classified data, labels, or clearances, and the company's rules are about job functions rather than data sensitivity. MAC would be unnecessarily rigid and does not map to the developer and release manager distinction.
- ✗
Rule-based access control, because conditions such as branch protection rules can restrict actions
Why it's wrong here
Rule-based access control evaluates explicit conditions, such as time, location, or network, to permit or deny access. While branch protection rules sound similar, they are policy conditions rather than an access control model driven by user attributes. The scenario is fundamentally about assigning permissions according to job roles, which points to a different model.
- ✓
Role-based access control (RBAC), because permissions are tied to job functions like developer and release manager
Why this is correct
RBAC assigns permissions to roles and users to roles, so developers receive read and commit rights while the release manager receives tag creation rights. Because the rules are defined centrally by role rather than by repository ownership, they apply consistently to everyone. This matches the company's requirement that the separation be enforced regardless of who owns the repository.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.