Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

A hospital uses a discretionary access control model on its file shares. A department head grants a colleague read access to a folder containing protected health information so they can cover a vacation. Months later an audit finds the access still active after the coverage ended. Which characteristic of discretionary access control most directly explains why this happened?

⚠ Common exam trap

The trap here is blaming the user for forgetting to revoke access, when the real cause is the model's decentralized owner-controlled grants.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Resource owners can grant access at their own discretion, and no central authority automatically removes it.

Discretionary access control places grant authority with resource owners, which is flexible but creates lifecycle risk because nothing forces revocation when the original justification disappears. The stale protected health information access persisted until an audit surfaced it. Recognizing this characteristic explains why the hospital needs centralized entitlement review, time-bound access requests, and automated revocation rather than simply retraining the department head.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Permissions are derived from the user's job role rather than from individual grants.

    Why it's wrong here

    Role-based access control ties entitlements to roles, so a temporary coverage assignment would normally be modeled as a time-bound role or an elevated request with an expiry. The scenario describes a one-off grant made directly by an owner, not a role assignment, so role derivation does not explain the persistence. Applying role logic here would not address the underlying discretionary grant.

  • ✗

    Access decisions are enforced by system-wide labels that owners cannot override.

    Why it's wrong here

    That describes mandatory access control, where sensitivity labels and clearances govern access and individual owners cannot loosen restrictions. In this hospital scenario the department head freely granted access, which is the opposite of label-based enforcement. Attributing the stale entitlement to immutable labels misidentifies the model in use and would lead to the wrong remediation approach.

  • ✓

    Resource owners can grant access at their own discretion, and no central authority automatically removes it.

    Why this is correct

    In discretionary access control the owner of a resource decides who receives access, and the system does not inherently revoke that access when the business need ends. Because the department head acted as owner and no centralized lifecycle process intervened, the permission persisted after the vacation coverage concluded. This decentralization of authority is the defining trait that produced the stale entitlement found during the audit.

  • ✗

    The system enforces a strict need-to-know policy using centralized administration.

    Why it's wrong here

    Centralized administration with strict need-to-know is characteristic of nondiscretionary or mandatory models, and it would typically include formal review and revocation. The hospital's problem is precisely the absence of centralized control, since a department head unilaterally extended access. Describing the environment as centrally administered contradicts the facts and would misdirect the audit finding.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.