Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?

⚠ Common exam trap

Many exam-takers confuse the container (OU) with the policy content (GPO) or the protocol (LDAP); candidates often pick GPO because the question mentions policies, missing that the question asks what organizes objects hierarchically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Organizational Units (OUs)

Organizational Units (OUs) are the container objects within Active Directory that provide the hierarchical structure used to organize users, groups, computers, and other objects. Because Group Policy can be linked directly to an OU, it is the primary mechanism for scoping policy application to a subset of the directory. This makes OUs the correct answer for organizing objects hierarchically for policy purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Organizational Units (OUs)

    Why this is correct

    Organizational Units are containers within Active Directory that hold users, groups and computers hierarchically, letting administrators link Group Policy Objects at specific levels. This hierarchical structure satisfies the stem's requirement for organising directory objects so policies apply appropriately.

  • ✗

    Group Policy Objects (GPOs)

    Why it's wrong here

    GPOs are policy containers linked to sites, domains and organisational units; they apply settings rather than form the hierarchy itself. GPOs are tempting because they are the visible policy mechanism, but they would be the answer if the question asked how policy settings are delivered to users and computers.

  • ✗

    Domain controllers

    Why it's wrong here

    Domain controllers authenticate accounts and replicate the directory database; they host the hierarchy rather than define it. Domain controllers are tempting because they are central to Active Directory, but they would be the answer if the question asked which server validates logons or holds the writable copy of the directory.

  • ✗

    LDAP

    Why it's wrong here

    LDAP is an access protocol for querying and modifying directory entries; it does not itself create the hierarchical container structure. LDAP is tempting because it is synonymous with directory access, but it would be the answer if the question asked how applications read or search directory data.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.