CC · domain
Access Controls Concepts
Domain 3 (Access Controls Concepts) covers how subjects are identified, authenticated, authorized, and held accountable for actions on assets. Expect scenario questions asking you to classify a control as preventive, detective, or corrective, to distinguish identification from authentication, and to match principles like least privilege, separation of duties, and need to know to short business situations.
Focused practice
Practice Access Controls Concepts questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Access Controls Concepts
Be able to read a short scenario and name the principle or control category it demonstrates, and to separate identification from authentication. The single most important thing: know that authentication proves identity, while authorization decides what that proven identity may access.
Distinguishing identification, authentication, authorization, and accountability in a given scenario
Applying least privilege, need to know, and separation of duties to described workflows
Classifying controls as administrative, technical, or physical and preventive, detective, or corrective
Recognizing authentication factors (something you know, have, are) and single sign-on concepts
Watch out for
Common Access Controls Concepts exam traps
- ▸Confusing identification with authentication: a username claims an identity, while a password, token, or biometric proves it.
- ▸Treating separation of duties and dual control as identical; dual control needs two people acting together, separation of duties splits a task across people.
- ▸Assuming role-based access control is the same as mandatory access control; RBAC uses job roles, MAC uses system-assigned labels.
Question index
All Access Controls Concepts questions (146)
Click any question to see the full explanation, or start a practice session above.
Which of the following is the primary purpose of a visitor log and escort policy?
Medium2A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?
Easy3A software company allows developers to access production servers only during an approved change window, and only after a manager approves a request that includes a ticket number and expiration time. Access is automatically revoked when the window closes. Which access control approach is being used?
Hard4A hospital's IT department issues every nurse a unique smart card that must be inserted into a workstation before the nurse types a password. The smart card alone does not grant access to patient records. Which access control concept does the smart card insertion represent?
Easy5A security analyst reviews server logs and sees that a single service account performed a login from an office workstation at 09:00 and then, two minutes later, executed administrative commands from an external IP address in another country. The account's password is long and complex. Which access control weakness does this pattern most likely indicate?
Medium6According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)
Hard7According to NIST SP 800-63, which password policy is most recommended?
Medium8A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?
Hard9In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?
Medium10A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?
Medium11An organization wants to implement defense in depth for its server room. Which THREE controls should be included?
Hard12Which access control principle restricts access to data based on the user's job role and tasks?
Easy13A hospital's IT team issues each nurse a unique smart card that is inserted into a workstation before the nurse types a password. The nurse then accesses patient records permitted for the assigned ward. Which combination of access control concepts is being demonstrated?
Easy14An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:
Medium15A defense contractor classifies documents as Confidential, Secret, or Top Secret and assigns each employee a clearance level. Access is permitted only when the employee's clearance meets or exceeds the document's classification, and users cannot change these labels. Which access control model is in use?
Hard16A retail company issues managers a hardware token that generates a one-time code, which they enter after their password when signing in to the payroll system. A help desk technician asks why the company does not simply require longer passwords instead. Which statement best explains the security benefit of the token?
Medium17An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)
Hard18Which of the following is an example of a logical access control?
Easy19In the identification and authentication process, which step occurs first?
Easy20A hospital's IT security team reviews how nurses access patient records. They find that a nurse who works in the cardiology unit can also open records for the oncology unit, even though the nurse never treats those patients. The team wants access decisions to be based on the department a nurse is assigned to plus the specific treatment relationship. Which access control model should they implement?
Medium21What is the process of claiming an identity called?
Easy22A security team is reviewing how access control is enforced across a corporate environment. Which two statements accurately describe the relationship between identification, authentication, and authorization? (Choose two.)
Medium23A small design studio stores client files on a shared server. Each project folder is owned by the designer who created it, and that designer decides which colleagues may open the folder by granting permissions directly to individual accounts. Which access control model is the studio using?
Easy24A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?
Medium25Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?
Easy26A retail company issues contract workers temporary accounts that automatically expire after 30 days, and it reviews all active accounts each quarter to remove those no longer needed. Which access control administration practice does the quarterly review represent?
Medium27An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?
Hard28A small marketing firm wants to give each employee a single set of credentials that works for the corporate email system, the cloud CRM, and the internal file share. The IT manager proposes using a central identity store so users do not have to remember separate passwords. Which concept is the IT manager describing?
Easy29An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)
Hard30An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?
Hard31A data center manager wants to strengthen physical access control at the main entrance while keeping the process practical for employees arriving each morning. Which two measures BEST align with sound physical access control practices? (Choose two.)
Medium32Which of the following is a recommended practice for administrative accounts?
Easy33According to NIST SP 800-63, which password policy is recommended to enhance security?
Medium34A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?
Easy35A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?
Medium36An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)
Hard37A financial services firm is designing controls to enforce separation of duties in its payment approval process. Which two practices support this goal? (Choose two.)
Hard38A payroll clerk can view and edit employee salary records but cannot approve her own expense reimbursements, even though she processes reimbursements for other staff. Which access control principle does the restriction on approving her own reimbursements best illustrate?
Easy39A security team is designing a physical access control system for a data center. They want to implement controls that verify a person's identity based on unique biological characteristics. Which two of the following are examples of biometric access controls? (Choose two.)
Medium40A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)
Hard41An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?
Hard42A financial services firm is deploying a new customer portal. Auditors have required that access decisions consider the user's department, the data classification of the record, the time of day, and whether the request originates from a managed corporate device. The security architect proposes Attribute-Based Access Control (ABAC). Which two statements correctly describe how ABAC satisfies these requirements? (Choose two.)
Hard43A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?
Hard44A Privileged Access Management (PAM) solution is used to:
Hard45An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?
Hard46An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?
Medium47A hospital's data center uses a mantrap at its main entrance. A nurse badges in at the outer door, steps into a small glass vestibule, and the outer door locks before the inner door unlocks. What security goal does this design primarily achieve?
Easy48Which TWO are examples of logical access controls? (Select TWO.)
Easy49A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?
Medium50An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?
Medium51In the context of identification and authentication, which of the following is an example of authentication?
Medium52A financial services firm classifies documents as Public, Internal, Confidential, and Restricted. Access to Restricted documents is determined solely by the document's classification label and the user's clearance level, and users cannot change either value. Which statement best describes this arrangement?
Medium53A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:
Medium54Which type of access control is implemented by a cable lock attached to a laptop?
Easy55A company's physical security includes fencing, security guards, access badges, and biometric locks on server room doors. This layered approach is an example of which access control concept?
Medium56A session timeout automatically logs out a user after a period of inactivity. This control primarily protects against:
Hard57An employee uses their username to claim an identity and then enters a password to prove it. What is the term for the process of proving the claimed identity?
Medium58A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)
Hard59A security administrator is configuring a session timeout policy. Which of the following are valid reasons for implementing session timeouts? (Choose TWO.)
Medium60Which THREE are key components of Active Directory? (Select THREE.)
Medium61A retail company is designing its access control program and wants to rely on attributes such as the user's department, the sensitivity label of the data, and the current time of day to make access decisions. Which TWO of the following statements accurately describe attribute-based access control (ABAC)? (Choose two.)
Medium62A new employee at a marketing firm receives a company laptop, a proximity badge, and a one-time password token on their first day. Before being allowed to log in, the employee must enter their employee ID, then a code from the token, then scan the badge. Which access control concept does the employee ID represent in this sequence?
Easy63An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:
Easy64Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)
Medium65A financial services firm grants tellers access to the transaction system only between 8:00 a.m. and 6:00 p.m. on business days, regardless of the teller's role. Access requests outside that window are automatically denied, and the restriction is enforced by a centrally managed policy that tellers cannot modify. Which access control approach is being applied?
Hard66A security analyst notices that an employee who transferred from Finance to Marketing still has full access to financial reporting systems six months later. The analyst wants to correct this through the access control lifecycle. Which action best addresses the root cause?
Hard67A hospital IT team is reviewing how staff access patient records. A nurse logs in with a unique employee ID, then enters a password plus a one-time code from a hardware token. The team wants to document which access control category this login process represents. Which category BEST describes this approach?
Easy68In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?
Hard69A defense contractor runs a facility where entry to the secure lab requires a fingerprint scan, and entry to the adjacent server cage additionally requires a retina scan. A security analyst is documenting the access control design for an audit. Which two statements accurately describe these controls? (Choose two.)
Hard70A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)
Hard71An account lockout policy is implemented to protect against which type of attack?
Medium72A security analyst is reviewing how a centralized authentication protocol validates user credentials before granting access to network resources. Which two characteristics correctly describe Kerberos authentication as used in a Windows domain environment? (Choose two.)
Hard73A software company uses a central identity provider so employees can sign in once and access email, the code repository, and the expense system without entering credentials again during the workday. The security team wants to describe the mechanism that lets the identity provider assert the user's identity to each application. Which technology is being used?
Medium74In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?
Medium75A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?
Hard76A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)
Medium77Which of the following best describes the purpose of a session timeout?
Easy78A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?
Medium79A financial services firm must enforce access decisions based on data sensitivity labels assigned by a central authority, and users cannot change these labels or grant access to others. Which access control model is the firm implementing?
Hard80An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?
Hard81In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?
Hard82A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?
Medium83A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?
Medium84A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?
Easy85An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?
Medium86A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?
Easy87A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?
Medium88What is the primary purpose of a Privileged Access Management (PAM) solution?
Medium89A user logs into a corporate portal by entering a username and password. The system then prompts for a one-time code from a mobile authenticator app. Which two factors of authentication are being combined in this scenario?
Easy90A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?
Medium91An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?
Hard92A hospital issues each nurse a unique username and a badge that is scanned at a workstation to prove the nurse's identity before any patient records can be opened. Which access control concept does scanning the badge to prove identity represent?
Easy93A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?
Medium94A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)
Medium95An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?
Hard96A new employee logs in to the corporate network for the first time by entering a username and password. The system checks the credentials against the directory and grants access. Which security concept does entering the username and password represent?
Easy97Which process involves verifying the identity of a user who claims to be a specific person?
Easy98Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?
Easy99An account lockout policy is designed to mitigate which type of attack?
Medium100A retail company is reviewing physical access controls at its data center. Management wants to document measures that restrict who can enter the server hall and record when entries occur. Which TWO of the following are physical access controls that meet these goals? (Choose two.)
Medium101A security analyst is reviewing an access control list on a file server and notices that a former employee's account still has read and write permissions, even though the account was disabled three months ago. Which access control practice failed in this situation?
Medium102Which TWO of the following are components of the identification and authentication process? (Select TWO.)
Medium103A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?
Medium104A small accounting firm wants to grant access to its tax software based on the department a user belongs to, rather than assigning permissions to each person individually. Which access control model should the firm implement to meet this requirement?
Medium105Which THREE are recommended practices for password policies according to current guidelines?
Medium106A financial services firm grants a contractor temporary access to a trading application for a 90-day engagement. The security team wants the access to expire automatically without manual intervention, and also wants the contractor's manager to periodically confirm the access is still required. Which combination of access control practices best satisfies both requirements?
Hard107A defense contractor classifies documents as Confidential, Secret, or Top Secret and requires that access decisions be based on these labels. Users receive clearances, and the system itself enforces that a user may read a document only if the user's clearance dominates the document's label. Users cannot change labels or grant access to others. Which access control model is being enforced?
Hard108A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?
Hard109An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?
Medium110Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?
Easy111A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?
Medium112Which of the following is a recommended practice for password security according to NIST SP 800-63?
Medium113A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?
Medium114A software company wants contractors to access an internal code repository only during their contracted hours and only from company-managed laptops. The repository administrator should implement which type of access control to meet these conditions?
Hard115A financial services firm assigns permissions based on each employee's role in the HR system. When an employee transfers from accounting to marketing, the HR record changes and the employee's access is automatically updated to match the marketing role. Which access control model is the firm using?
Medium116A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?
Medium117A financial services firm stores customer records in a database. A teller can read and update records for customers assigned to their branch but cannot view records belonging to other branches. A branch manager can view all records within their region. Which access control principle best explains why the teller's access is limited to their own branch's customers?
Medium118Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?
Easy119A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?
Medium120A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)
Hard121A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?
Hard122Which THREE of the following are best practices for privileged account management? (Select THREE.)
Medium123An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?
Easy124A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?
Medium125A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?
Medium126A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?
Hard127A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?
Medium128A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?
Easy129An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?
Hard130A defense contractor classifies documents as Public, Internal, Secret, and Top Secret. A user with Secret clearance attempts to open a Top Secret document and is denied, while a user with Top Secret clearance can open both Top Secret and Secret documents. Which access control model does this behavior describe?
Hard131What is the difference between identification and authentication?
Easy132A hospital's IT team assigns each doctor a unique smart card that must be inserted before the workstation unlocks, and the card's embedded certificate is validated against the hospital's internal certificate authority. Which access control process does the smart card insertion and certificate validation represent?
Medium133A hospital's IT team wants to ensure that nurses can access patient records only during their assigned 12-hour shifts, even if their credentials are valid around the clock. Which access control model should the team implement to enforce this time-based restriction?
Medium134An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?
Easy135A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)
Medium136A hospital's billing application assigns permissions based on each employee's job title, such as nurse, billing clerk, or department manager. When an employee changes roles, the administrator updates the job title and the application automatically adjusts the employee's access. Which access control model is being used?
Medium137An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?
Hard138According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?
Medium139A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?
Hard140A payroll clerk changes roles within the same company, moving from the finance department to the human resources department. The security team discovers months later that the clerk still retains all the finance application permissions from the previous position in addition to the new HR permissions. Which access control weakness does this situation illustrate?
Easy141An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?
Medium142A hospital's radiology department issues each technologist a smart card that must be inserted into a workstation reader before the technologist types a username and password. The smart card stores a digital certificate that the workstation validates. Which statement best describes how this arrangement maps to the identity and access control concepts?
Medium143A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)
Hard144An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?
Hard145A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?
Medium146A retail chain wants store managers to approve refunds above $500, but the managers should not be able to approve their own refund transactions. The security team must enforce this separation in the point-of-sale system. Which access control model best fits this requirement?
MediumOther domains
All CC exam domains
Frequently asked questions
- What does the Access Controls Concepts domain cover on the CC exam?
- Be able to read a short scenario and name the principle or control category it demonstrates, and to separate identification from authentication. The single most important thing: know that authentication proves identity, while authorization decides what that proven identity may access.
- How many questions are in this domain?
- This page lists all 146 Access Controls Concepts questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Access Controls Concepts questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.