SSCP Access Controls Practice Question
A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?
⚠ Common exam trap
SSCP often tests the distinction between RBAC (job-function roles and hierarchy), DAC (owner-controlled), MAC (labels/clearances), and ABAC (attributes) — candidates who confuse role hierarchy with attribute-based rules pick E or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Roles can be organized in a hierarchy to inherit permissions
Option A is correct because RBAC supports role hierarchies, where a senior role (e.g., Manager) inherits the permissions of a junior role (e.g., Employee), which is a core RBAC capability for structuring permissions efficiently. Option B is correct because the defining characteristic of RBAC is assigning users to roles according to their job functions or responsibilities, and permissions are then granted to those roles rather than to individual users. Option C is incorrect because control by the data owner describes discretionary access control (DAC), not RBAC. Option D is incorrect because assigning permissions directly to users is the opposite of RBAC, which assigns permissions to roles. Option E is incorrect because access decisions based on subject and object attributes describe attribute-based access control (ABAC), not RBAC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Roles can be organized in a hierarchy to inherit permissions
Why this is correct
Role hierarchies let senior roles inherit permissions from junior ones, so a manager role automatically gains the permissions assigned to the employee role beneath it. This satisfies RBAC's structural requirement that permissions attach to roles rather than individual users, reducing administrative overhead when many users share common access needs.
- ✓
Users are assigned to roles based on their job functions
Why this is correct
Assigning users to roles by job function is the core RBAC construct: permissions attach to roles, and roles attach to users, so access derives from organisational responsibility rather than individual identity. This satisfies the stem's RBAC model requirement, since role membership is determined by the duties a user performs, not by discretionary per-user grants.
- ✗
Access is controlled by the data owner
Why it's wrong here
RBAC grants access through assigned roles, not data-owner discretion; ownership-based control describes discretionary access control (DAC). It tempts because data owners do define access in DAC deployments, but RBAC derives permissions from the role definition itself, so ownership is irrelevant to the role-permission mapping.
- ✗
Permissions are assigned directly to users
Why it's wrong here
RBAC assigns permissions to roles, and users acquire them through role membership; direct user-permission assignment is the defining trait of discretionary access control. It tempts because direct assignment works in small environments, but it defeats the role abstraction RBAC requires.
- ✗
Access decisions are based on subject and object attributes
Why it's wrong here
Subject and object attributes drive attribute-based access control (ABAC), not RBAC, which maps permissions to roles rather than evaluating attributes at request time. It tempts because ABAC is a valid access-control model, but the stem specifies role-based access, where the role assignment, not attribute evaluation, determines access.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.