SSCP Access Controls Practice Question
A healthcare organization deploys a new electronic records system. Clinicians may access patient records only while assigned to the cardiology department, and access is automatically revoked when they rotate to oncology. Which access control model best supports this requirement?
⚠ Common exam trap
The trap here is assuming that any model capable of expressing department membership, such as ABAC, is equally suitable, when the scenario is specifically about role assignments that change with job rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based access control (RBAC)
The requirement ties access to a clinician's current department and revokes it upon rotation, which is precisely how role-based access control operates. Permissions are grouped into roles, and users receive access only through their assigned roles. When the cardiology role assignment is removed during rotation, access ends automatically, while the oncology role grants the appropriate new access. This makes RBAC the most natural and administratively efficient fit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Role-based access control (RBAC)
Why this is correct
RBAC assigns permissions to roles rather than individuals, so a clinician's cardiology role grants record access only while assigned to it. Rotating to oncology means the cardiology role assignment is removed and the oncology role takes over, automatically changing access. This matches the requirement that access be tied to department membership and revoked upon rotation without per-user intervention.
- ✗
Discretionary access control (DAC)
Why it's wrong here
DAC allows the owner of a resource to decide who may access it and with what rights, so access would depend on clinician or data-owner discretion rather than on organizational role assignments. It cannot automatically revoke access when a clinician rotates departments, because rights are granted directly by owners and persist until changed manually, which conflicts with the requirement for dynamic, role-driven enforcement.
- ✗
Attribute-based access control (ABAC)
Why it's wrong here
ABAC evaluates attributes about the subject, object, and environment, which could theoretically express department membership, but it is more complex than necessary for this scenario. The requirement is directly about organizational roles, and RBAC expresses that relationship natively. ABAC would demand additional policy authoring and attribute sources, increasing administrative overhead without a clear advantage for simple department-based access.
- ✗
Mandatory access control (MAC)
Why it's wrong here
MAC enforces access using system-wide labels and clearances that administrators cannot override at the user's discretion, which is more rigid than needed here. Although MAC provides strong control, it does not naturally model organizational department membership or automatically adjust rights when a clinician transfers between units, so it would require extensive label administration and would not cleanly satisfy the rotation-based revocation requirement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.