ISC2 CC Access Controls Concepts Practice Question
In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?
⚠ Common exam trap
Many exam-takers confuse the container (OU) with the policy content (GPO) or the protocol (LDAP); candidates often pick GPO because the question mentions policies, missing that the question asks what organizes objects hierarchically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organizational Units (OUs)
Organizational Units (OUs) are the container objects within Active Directory that provide the hierarchical structure used to organize users, groups, computers, and other objects. Because Group Policy can be linked directly to an OU, it is the primary mechanism for scoping policy application to a subset of the directory. This makes OUs the correct answer for organizing objects hierarchically for policy purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Organizational Units (OUs)
Why this is correct
Organizational Units are containers within Active Directory that hold users, groups and computers hierarchically, letting administrators link Group Policy Objects at specific levels. This hierarchical structure satisfies the stem's requirement for organising directory objects so policies apply appropriately.
- ✗
Group Policy Objects (GPOs)
Why it's wrong here
GPOs are policy containers linked to sites, domains and organisational units; they apply settings rather than form the hierarchy itself. GPOs are tempting because they are the visible policy mechanism, but they would be the answer if the question asked how policy settings are delivered to users and computers.
- ✗
Domain controllers
Why it's wrong here
Domain controllers authenticate accounts and replicate the directory database; they host the hierarchy rather than define it. Domain controllers are tempting because they are central to Active Directory, but they would be the answer if the question asked which server validates logons or holds the writable copy of the directory.
- ✗
LDAP
Why it's wrong here
LDAP is an access protocol for querying and modifying directory entries; it does not itself create the hierarchical container structure. LDAP is tempting because it is synonymous with directory access, but it would be the answer if the question asked how applications read or search directory data.
Go deeper
Related to this question
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.