ISC2 CC Access Controls Concepts Practice Question
An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?
⚠ Common exam trap
A common mix-up: candidates confuse domain components (DC) with organizational units (OU). Candidates might incorrectly select DC=company as the OU because it sounds like an organizational name, but DC always denotes a domain component, not an OU.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OU=Sales
In an LDAP distinguished name (DN), each component is identified by its attribute type. The organizational unit (OU) is represented by the 'OU=' attribute. In the given DN, 'OU=Sales' explicitly designates the organizational unit named 'Sales'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
OU=Sales
Why this is correct
OU=Sales identifies the organizational unit, since the OU attribute type in a distinguished name denotes a container within the directory hierarchy. The stem asks specifically which component represents the organizational unit, and this value directly satisfies that constraint, distinguishing it from CN (common name) and DC (domain component) elements.
- ✗
DC=com
Why it's wrong here
DC denotes a domain component, so DC=com identifies the top-level domain portion of the DN, not the organizational unit. OU=Sales is the organizational unit. DC would be the right answer if the question asked which component represents the domain, not the OU.
- ✗
CN=John Smith
Why it's wrong here
CN denotes the common name, so CN=John Smith identifies the person or object itself, not the organizational unit. OU=Sales is the organizational unit. CN would be the right answer if the question asked which component names the entry or user.
- ✗
DC=company
Why it's wrong here
DC=company denotes a domain component, the DNS-based naming level of the directory tree, not an organizational unit. It is tempting because domain components sit alongside OUs in a DN and both scope directory objects, so DC would be the answer if the question asked for the domain rather than the OU.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.