Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

A company uses discretionary access control (DAC) for its file shares. A project manager creates a folder and wants to grant a team member read-only access. Which of the following best describes how access is determined in this model?

⚠ Common exam trap

A common mix-up: candidates confuse DAC with RBAC or MAC, assuming that access is determined by roles or labels rather than by the resource owner's discretion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The project manager, as the owner of the folder, can set the permissions for the team member.

Discretionary access control (DAC) is characterized by the owner of the resource having the ability to determine who can access it and with what permissions. In this scenario, the project manager owns the folder and can grant read-only access to the team member. The other options describe characteristics of MAC, RBAC, or administrative approval processes, which are not inherent to DAC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The team member must request access through a centralized approval workflow.

    Why it's wrong here

    A centralized approval workflow is typical of RBAC or MAC systems, where access is managed by administrators or automated processes. In DAC, the owner can directly grant access without a formal workflow. The project manager can simply set the permissions on the folder.

  • ✓

    The project manager, as the owner of the folder, can set the permissions for the team member.

    Why this is correct

    In discretionary access control, the owner of a resource has the discretion to grant or revoke access. Since the project manager created the folder, they are the owner and can assign read-only permission to the team member. This is the defining characteristic of DAC.

  • ✗

    The team member's access is determined by their role in the organization.

    Why it's wrong here

    Role-based access control (RBAC) determines access based on roles. While RBAC may be used in conjunction with DAC, the scenario specifies DAC, where the owner decides. The team member's role is not the primary factor in DAC; the owner's discretion is.

  • ✗

    The system administrator must assign a label to the folder and the user's clearance.

    Why it's wrong here

    This describes mandatory access control (MAC), where labels and clearances determine access. In DAC, the owner of the resource decides permissions. The scenario states DAC is used, so administrative labeling is not involved. The project manager, as owner, can set permissions without administrator intervention.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.