ISC2 CC Access Controls Concepts Practice Question
An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?
⚠ Common exam trap
The trap is the DC acronym collision — candidates who work with Active Directory reflexively read DC as Domain Controller instead of Domain Component.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OU = Organizational Unit; DC = Domain Component
In LDAP distinguished names, OU stands for Organizational Unit and DC stands for Domain Component. These are the standard RDN attribute types defined in RFC 4519 and used to build hierarchical directory paths, so option A is the correct expansion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
OU = Organizational Unit; DC = Domain Component
Why this is correct
In LDAP distinguished names, OU identifies the Organizational Unit container holding the object, while DC marks each Domain Component of the DNS-based directory namespace. Reading right to left, DC=com and DC=company define the domain hierarchy, and OU=Sales places John Smith within the Sales organisational unit.
- ✗
OU = Organizational Unit; DC = Domain Controller
Why it's wrong here
DC stands for Domain Component, not Domain Controller; the DN's DC attributes denote the DNS domain hierarchy, such as company.com. It is tempting because domain controllers are the servers that authenticate against Active Directory, so the abbreviation appears contextually related to LDAP directories.
- ✗
OU = Organizational Unit; DC = Distinguished Component
Why it's wrong here
DC denotes Domain Component, not Distinguished Component; the DN's DC attributes represent the DNS domain hierarchy, such as company.com. It is tempting because the term distinguished name appears in the same DN syntax, making 'Distinguished Component' sound like a plausible expansion.
- ✗
OU = Object Unit; DC = Domain Component
Why it's wrong here
OU stands for Organizational Unit, not Object Unit; OUs are containers within the directory tree holding users and groups. It is tempting because LDAP entries are objects, so 'Object Unit' sounds like a container naming objects, but the standard expansion is Organizational Unit.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Lightweight Directory Access Protocol
Lightweight Directory Access Protocol (LDAP) is a standard protocol used to access and manage directory information over a network, such as user credentials and permissions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.