Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

A healthcare organization must enforce access control based on a combination of the user's assigned department, the classification of the data being accessed, and the time of day. Users in the cardiology department may view patient records only during their scheduled shift, and only if the record belongs to a patient currently admitted to cardiology. Which access control model BEST supports these requirements?

⚠ Common exam trap

The trap here is assuming that role membership alone is sufficient for context-sensitive access, when in fact temporal and data-context conditions require attribute-based evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attribute-Based Access Control (ABAC)

Attribute-Based Access Control is designed for policy decisions that combine multiple characteristics of the user, the resource, and the environment. Department, data classification, shift time, and a patient's current admission status are all attributes that can be evaluated in a single rule, so access is granted only when every condition is satisfied. The other models rely on ownership, static labels, or roles that cannot express these dynamic, contextual constraints together.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-Based Access Control (RBAC)

    Why it's wrong here

    RBAC grants permissions based on a user's role, such as cardiology nurse, and is well suited to job-function mapping. However, RBAC alone cannot dynamically combine department, data classification, time of day, and patient admission status in a single policy decision. Meeting all the stated conditions would require extensive role explosion, and RBAC still would not enforce the temporal and patient-context constraints.

  • ✓

    Attribute-Based Access Control (ABAC)

    Why this is correct

    ABAC evaluates attributes of the subject, object, action, and environment, which maps directly to department, data classification, time of day, and patient admission status. Policies written as boolean rules can require all conditions to be true before granting access, delivering the fine-grained, context-aware decisions this scenario demands. This makes ABAC the appropriate model for combining multiple dynamic factors into one authorization decision.

  • ✗

    Discretionary Access Control (DAC)

    Why it's wrong here

    DAC lets resource owners set permissions at their discretion, which cannot reliably enforce organization-wide rules tying department, data classification, and time of day together. In this scenario, a record owner could grant access to anyone regardless of shift or admitting department, violating the stated policy. DAC lacks the centralized, policy-driven decision engine needed to evaluate the multiple contextual attributes simultaneously.

  • ✗

    Mandatory Access Control (MAC)

    Why it's wrong here

    MAC enforces access through system-assigned labels such as sensitivity levels and clearances, but it does not natively evaluate dynamic conditions like time of day or a patient's current admission status. The scenario requires contextual, attribute-driven decisions that MAC's static label comparison does not provide. MAC would restrict based on classification and clearance alone, missing the shift and admission criteria.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.