SSCP Access Controls Practice Question
A defense contractor runs an air-gapped laboratory where removable media are used to move engineering data between isolated enclaves. Policy requires that a workstation be usable only when a specific approved removable device is inserted, and that the workstation become unusable the instant that device is removed. Which access control approach best enforces this behavior?
⚠ Common exam trap
The trap here is reaching for a strong logical control such as multifactor authentication when the requirement is actually about physical presence of a specific object.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a hardware token interlock that permits operation only while the approved device is physically engaged
The policy couples system availability to the physical presence of one approved object, which is a property of a hardware interlock rather than of any logical permission scheme. Interlocks act at the level of the machine itself, so the workstation cannot operate without the device and cannot continue operating after the device is removed, regardless of who is logged on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a hardware token interlock that permits operation only while the approved device is physically engaged
Why this is correct
A hardware interlock is a physical control that couples system operation to the presence of a specific object, so the workstation runs only with the approved device inserted and stops the moment it is withdrawn. This directly satisfies both halves of the policy without relying on software that could be bypassed.
- ✗
Require multifactor authentication with a smart card before any user may log on to the workstation
Why it's wrong here
Strong authentication verifies the user at logon, but once the session is established it does not monitor the physical environment. A user could authenticate with a smart card while an unapproved device was attached, and removing the approved device after logon would have no effect on the running session, so the policy would be violated.
- ✗
Deploy a role-based policy that grants laboratory staff access to the enclave during working hours
Why it's wrong here
Time-bound role membership controls who may work and when, but it does not observe whether a physical device is present. A workstation would remain usable with no approved media inserted and would stay usable after the device was pulled, so the presence-and-removal requirement goes entirely unmet by this approach.
- ✗
Apply discretionary access control so that file owners may share engineering data only with vetted colleagues
Why it's wrong here
Discretionary access control governs which subjects may read or modify files, not whether hardware is attached to the machine. It has no mechanism to detect device insertion or removal, and its owner-driven grants introduce exactly the flexibility the contractor wants to eliminate in an air-gapped laboratory where media control is paramount.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.