Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

A hospital is deploying a new electronic health records (EHR) system. The security team wants to ensure that access decisions are based on the user's assigned job function rather than on the user's identity or resource ownership. Which access control model best meets this requirement?

⚠ Common exam trap

A common mix-up: candidates confuse role-based access with rule-based access, assuming that any rule or policy that references job functions qualifies as RBAC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) is designed to assign permissions to roles, and users are then assigned to roles according to their job responsibilities. This directly satisfies the hospital's requirement that access be based on job function rather than individual identity or resource ownership. The other models either rely on ownership, labels, or global rules, which do not meet the stated need.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Discretionary Access Control (DAC)

    Why it's wrong here

    DAC allows the owner of a resource to decide who can access it. In the hospital EHR scenario, this would mean individual users or departments could grant access at their discretion, which does not enforce consistent, job-function-based access. DAC is identity- and ownership-centric, not role-centric, so it fails the stated requirement.

  • ✗

    Mandatory Access Control (MAC)

    Why it's wrong here

    MAC bases access on security labels (e.g., classification levels) and clearances, not on job functions. While MAC is highly secure, it does not map naturally to the hospital's need for job-function-based access to EHR functions. Implementing MAC would require labeling data and users, which is not the same as assigning roles by job function.

  • ✓

    Role-Based Access Control (RBAC)

    Why this is correct

    RBAC assigns permissions to roles, and users are assigned to roles based on their job functions. In the hospital scenario, this means access to EHR functions is determined by the user's role (e.g., physician, nurse, billing clerk), not by individual identity or ownership. This aligns exactly with the requirement that access decisions be based on job function.

  • ✗

    Rule-Based Access Control

    Why it's wrong here

    Rule-based access control uses global rules, often for network devices (e.g., firewall ACLs), rather than assigning permissions to roles based on job functions. In the hospital scenario, rule-based access would not provide the structured, job-function-centric access model required. It is typically used for system-level enforcement, not for mapping users to job roles.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.