Courseiva
Access Controls →easyMultiple Select

SSCP Access Controls Practice Question

A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access rules are defined by the system, not users.

MAC uses labels for subjects and objects, and access decisions are based on clearance and classification. Users cannot change permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Permissions are assigned to roles.

    Why it's wrong here

    Assigning permissions to roles describes RBAC, where access derives from a user's job function; MAC instead binds subjects to clearance levels and objects to labels via a central policy. RBAC is tempting because it also centralises administration, and would be correct for simplifying entitlement management across many users.

  • ✓

    Access rules are defined by the system, not users.

    Why this is correct

    Mandatory Access Control enforces access decisions through a central authority using security labels and clearances, so users cannot alter permissions themselves. This satisfies the high-security constraint, where only the system assigns sensitivity labels and determines access, preventing user discretion or ownership-based control that discretionary models permit.

  • ✗

    Users can grant access to other users.

    Why it's wrong here

    Under MAC, labels and clearances are set by the system's security policy, and users cannot delegate their own access to others. The temptation is that discretionary sharing resembles role-based delegation, which belongs to DAC or RBAC; MAC would be correct where central policy, not user choice, governs every access decision.

  • ✓

    Subjects and objects have security labels.

    Why this is correct

    Security labels on both subjects and objects are the defining mechanism of MAC: the system compares the subject's clearance label against the object's classification label to authorise access. This satisfies the high-security constraint, since users cannot alter labels or grant access themselves, unlike discretionary models where owners set permissions.

  • ✗

    Access is based on the owner's discretion.

    Why it's wrong here

    Owner discretion defines DAC, where the resource owner decides who may access it; MAC instead enforces system-wide policy comparing subject clearance against object labels. DAC is tempting because it is the default model on most file systems, and would be correct in low-security settings where flexible sharing outweighs strict control.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.