Courseiva
Access Controls →mediumMultiple Select

SSCP Access Controls Practice Question

A financial services firm is deploying a centralized access control server that will make authorization decisions for dozens of internal applications. The architects want the applications to query a single decision point instead of embedding their own permission logic. Which two characteristics should the chosen model exhibit? (Choose two.)

⚠ Common exam trap

The trap here is equating centralization with speed, and therefore choosing local permission copies that quietly rebuild the fragmented logic the project set out to remove.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization decisions are expressed as policy that can be updated centrally and take effect without redeploying applications

Centralized authorization requires a shared decision point that evaluates rich context and a policy store that can be changed without touching application code. Attribute-based access control delivers both by evaluating subject, object, and environmental attributes in a central engine, and by expressing rules as centrally managed policy rather than as logic embedded in each application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Each application maintains its own copy of the permission tables so decisions can be made without network calls

    Why it's wrong here

    Distributing permission tables to every application recreates the fragmented logic the architects are trying to eliminate, and it guarantees inconsistency when a policy changes. The stated goal is one decision point, so local copies contradict the requirement even though they would reduce latency and dependence on the central service.

  • ✗

    Permissions are baked into each application's source code during development and released through the change management pipeline

    Why it's wrong here

    Embedding permissions in application code forces every policy change through development, testing, and release, which is slow and error prone. It also scatters the rules across teams, making a consistent view of who can do what nearly impossible. This is the anti-pattern the centralized decision point is meant to replace.

  • ✓

    Authorization decisions are expressed as policy that can be updated centrally and take effect without redeploying applications

    Why this is correct

    Centralized policy authoring means a change to rules propagates to all protected applications through the shared decision point rather than through code releases. This satisfies the architectural intent directly: the firm gains consistent enforcement and can adjust entitlements quickly, with the applications remaining unaware of the underlying rule changes.

  • ✓

    A central policy engine evaluates subject, object, and environmental attributes at the moment of each request

    Why this is correct

    Attribute-based access control evaluates policy against attributes of the requester, the resource, and the context such as time or network location, and it is designed to be centralized. A single policy engine answering each request is exactly the architecture described, and it removes duplicated permission logic from the individual applications.

  • ✗

    The decision point grants access based solely on the user's job title stored in the human resources system

    Why it's wrong here

    A single static attribute such as job title cannot express the nuanced conditions these applications need, and it ignores resource and environmental context. Attribute-based policy deliberately combines multiple attributes, so restricting evaluation to one field would produce both over-permissioning and wrongful denials, defeating the purpose of the centralized engine.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.