easyMultiple Choice
SSCP Access Control List (ACL) Practice Question
A company is implementing a new file-sharing application for employees. Which of the following is the most important security control to prevent unauthorized access to shared files?
⚠ Common exam trap
The SSCP exam often tests the misconception that encryption or audit logging prevents unauthorized access, when actually access control mechanisms like ACLs are the primary preventive control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement access control lists (ACLs) on shared folders.
Implementing access control lists (ACLs) on shared folders is the most direct and effective control to prevent unauthorized access to shared files. ACLs define which users or groups have permissions to read, write, or execute files, thereby enforcing the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Schedule regular backups.
Why it's wrong here
Backups restore availability and integrity after loss, ransomware or corruption; they grant no control over who may open a shared file. Regular backups are the right choice when the requirement is disaster recovery or business continuity, not access control.
- ✓
Implement access control lists (ACLs) on shared folders.
Why this is correct
ACLs enforce per-user and per-group permissions directly on shared folders, so only explicitly authorised identities can read or modify files. This satisfies the stem's requirement to prevent unauthorised access at the resource itself, rather than relying on perimeter controls that leave files exposed once a share is reached.
- ✗
Install antivirus software on all endpoints.
Why it's wrong here
Antivirus detects and removes malicious code on endpoints, but a legitimate employee with excessive permissions can still open and copy shared files. Endpoint antivirus is the correct control against malware infection, not against unauthorised access by authenticated users.
- ✗
Enable detailed audit logging.
Why it's wrong here
Audit logging records access after it occurs, providing detection and accountability rather than preventing unauthorised access. Logging is the right control for forensic investigation, compliance evidence or intrusion detection, but it cannot stop a user or attacker from opening a file they should not reach.
- ✗
Encrypt files with AES-256.
Why it's wrong here
AES-256 protects data confidentiality at rest and in transit, but anyone who obtains the decryption key or valid credentials can still read the files; authorisation is not enforced by encryption. Encryption is the correct control when files leave the organisation's trusted boundary, such as on removable media or in cloud storage.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.