Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

A healthcare organization deploys a new electronic records system. Clinicians may access patient records only while assigned to the cardiology department, and access is automatically revoked when they rotate to oncology. Which access control model best supports this requirement?

⚠ Common exam trap

The trap here is assuming that any model capable of expressing department membership, such as ABAC, is equally suitable, when the scenario is specifically about role assignments that change with job rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-based access control (RBAC)

The requirement ties access to a clinician's current department and revokes it upon rotation, which is precisely how role-based access control operates. Permissions are grouped into roles, and users receive access only through their assigned roles. When the cardiology role assignment is removed during rotation, access ends automatically, while the oncology role grants the appropriate new access. This makes RBAC the most natural and administratively efficient fit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Role-based access control (RBAC)

    Why this is correct

    RBAC assigns permissions to roles rather than individuals, so a clinician's cardiology role grants record access only while assigned to it. Rotating to oncology means the cardiology role assignment is removed and the oncology role takes over, automatically changing access. This matches the requirement that access be tied to department membership and revoked upon rotation without per-user intervention.

  • ✗

    Discretionary access control (DAC)

    Why it's wrong here

    DAC allows the owner of a resource to decide who may access it and with what rights, so access would depend on clinician or data-owner discretion rather than on organizational role assignments. It cannot automatically revoke access when a clinician rotates departments, because rights are granted directly by owners and persist until changed manually, which conflicts with the requirement for dynamic, role-driven enforcement.

  • ✗

    Attribute-based access control (ABAC)

    Why it's wrong here

    ABAC evaluates attributes about the subject, object, and environment, which could theoretically express department membership, but it is more complex than necessary for this scenario. The requirement is directly about organizational roles, and RBAC expresses that relationship natively. ABAC would demand additional policy authoring and attribute sources, increasing administrative overhead without a clear advantage for simple department-based access.

  • ✗

    Mandatory access control (MAC)

    Why it's wrong here

    MAC enforces access using system-wide labels and clearances that administrators cannot override at the user's discretion, which is more rigid than needed here. Although MAC provides strong control, it does not naturally model organizational department membership or automatically adjust rights when a clinician transfers between units, so it would require extensive label administration and would not cleanly satisfy the rotation-based revocation requirement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.