SSCP Access Controls Practice Question
A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access rules are defined by the system, not users.
MAC uses labels for subjects and objects, and access decisions are based on clearance and classification. Users cannot change permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permissions are assigned to roles.
Why it's wrong here
Assigning permissions to roles describes RBAC, where access derives from a user's job function; MAC instead binds subjects to clearance levels and objects to labels via a central policy. RBAC is tempting because it also centralises administration, and would be correct for simplifying entitlement management across many users.
- ✓
Access rules are defined by the system, not users.
Why this is correct
Mandatory Access Control enforces access decisions through a central authority using security labels and clearances, so users cannot alter permissions themselves. This satisfies the high-security constraint, where only the system assigns sensitivity labels and determines access, preventing user discretion or ownership-based control that discretionary models permit.
- ✗
Users can grant access to other users.
Why it's wrong here
Under MAC, labels and clearances are set by the system's security policy, and users cannot delegate their own access to others. The temptation is that discretionary sharing resembles role-based delegation, which belongs to DAC or RBAC; MAC would be correct where central policy, not user choice, governs every access decision.
- ✓
Subjects and objects have security labels.
Why this is correct
Security labels on both subjects and objects are the defining mechanism of MAC: the system compares the subject's clearance label against the object's classification label to authorise access. This satisfies the high-security constraint, since users cannot alter labels or grant access themselves, unlike discretionary models where owners set permissions.
- ✗
Access is based on the owner's discretion.
Why it's wrong here
Owner discretion defines DAC, where the resource owner decides who may access it; MAC instead enforces system-wide policy comparing subject clearance against object labels. DAC is tempting because it is the default model on most file systems, and would be correct in low-security settings where flexible sharing outweighs strict control.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.