SSCP Access Controls Practice Question
A hospital is deploying a new electronic health records (EHR) system. The security team wants to ensure that access decisions are based on the user's assigned job function rather than on the user's identity or resource ownership. Which access control model best meets this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse role-based access with rule-based access, assuming that any rule or policy that references job functions qualifies as RBAC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) is designed to assign permissions to roles, and users are then assigned to roles according to their job responsibilities. This directly satisfies the hospital's requirement that access be based on job function rather than individual identity or resource ownership. The other models either rely on ownership, labels, or global rules, which do not meet the stated need.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Discretionary Access Control (DAC)
Why it's wrong here
DAC allows the owner of a resource to decide who can access it. In the hospital EHR scenario, this would mean individual users or departments could grant access at their discretion, which does not enforce consistent, job-function-based access. DAC is identity- and ownership-centric, not role-centric, so it fails the stated requirement.
- ✗
Mandatory Access Control (MAC)
Why it's wrong here
MAC bases access on security labels (e.g., classification levels) and clearances, not on job functions. While MAC is highly secure, it does not map naturally to the hospital's need for job-function-based access to EHR functions. Implementing MAC would require labeling data and users, which is not the same as assigning roles by job function.
- ✓
Role-Based Access Control (RBAC)
Why this is correct
RBAC assigns permissions to roles, and users are assigned to roles based on their job functions. In the hospital scenario, this means access to EHR functions is determined by the user's role (e.g., physician, nurse, billing clerk), not by individual identity or ownership. This aligns exactly with the requirement that access decisions be based on job function.
- ✗
Rule-Based Access Control
Why it's wrong here
Rule-based access control uses global rules, often for network devices (e.g., firewall ACLs), rather than assigning permissions to roles based on job functions. In the hospital scenario, rule-based access would not provide the structured, job-function-centric access model required. It is typically used for system-level enforcement, not for mapping users to job roles.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.