Courseiva
Access Controls →easyMultiple Select

SSCP Access Controls Practice Question

A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?

⚠ Common exam trap

SSCP often tests the distinction between RBAC (job-function roles and hierarchy), DAC (owner-controlled), MAC (labels/clearances), and ABAC (attributes) — candidates who confuse role hierarchy with attribute-based rules pick E or C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Roles can be organized in a hierarchy to inherit permissions

Option A is correct because RBAC supports role hierarchies, where a senior role (e.g., Manager) inherits the permissions of a junior role (e.g., Employee), which is a core RBAC capability for structuring permissions efficiently. Option B is correct because the defining characteristic of RBAC is assigning users to roles according to their job functions or responsibilities, and permissions are then granted to those roles rather than to individual users. Option C is incorrect because control by the data owner describes discretionary access control (DAC), not RBAC. Option D is incorrect because assigning permissions directly to users is the opposite of RBAC, which assigns permissions to roles. Option E is incorrect because access decisions based on subject and object attributes describe attribute-based access control (ABAC), not RBAC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Roles can be organized in a hierarchy to inherit permissions

    Why this is correct

    Role hierarchies let senior roles inherit permissions from junior ones, so a manager role automatically gains the permissions assigned to the employee role beneath it. This satisfies RBAC's structural requirement that permissions attach to roles rather than individual users, reducing administrative overhead when many users share common access needs.

  • ✓

    Users are assigned to roles based on their job functions

    Why this is correct

    Assigning users to roles by job function is the core RBAC construct: permissions attach to roles, and roles attach to users, so access derives from organisational responsibility rather than individual identity. This satisfies the stem's RBAC model requirement, since role membership is determined by the duties a user performs, not by discretionary per-user grants.

  • ✗

    Access is controlled by the data owner

    Why it's wrong here

    RBAC grants access through assigned roles, not data-owner discretion; ownership-based control describes discretionary access control (DAC). It tempts because data owners do define access in DAC deployments, but RBAC derives permissions from the role definition itself, so ownership is irrelevant to the role-permission mapping.

  • ✗

    Permissions are assigned directly to users

    Why it's wrong here

    RBAC assigns permissions to roles, and users acquire them through role membership; direct user-permission assignment is the defining trait of discretionary access control. It tempts because direct assignment works in small environments, but it defeats the role abstraction RBAC requires.

  • ✗

    Access decisions are based on subject and object attributes

    Why it's wrong here

    Subject and object attributes drive attribute-based access control (ABAC), not RBAC, which maps permissions to roles rather than evaluating attributes at request time. It tempts because ABAC is a valid access-control model, but the stem specifies role-based access, where the role assignment, not attribute evaluation, determines access.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.