SSCP Access Controls Practice Question
A hospital uses a discretionary access control model on its file shares. A department head grants a colleague read access to a folder containing protected health information so they can cover a vacation. Months later an audit finds the access still active after the coverage ended. Which characteristic of discretionary access control most directly explains why this happened?
⚠ Common exam trap
The trap here is blaming the user for forgetting to revoke access, when the real cause is the model's decentralized owner-controlled grants.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resource owners can grant access at their own discretion, and no central authority automatically removes it.
Discretionary access control places grant authority with resource owners, which is flexible but creates lifecycle risk because nothing forces revocation when the original justification disappears. The stale protected health information access persisted until an audit surfaced it. Recognizing this characteristic explains why the hospital needs centralized entitlement review, time-bound access requests, and automated revocation rather than simply retraining the department head.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permissions are derived from the user's job role rather than from individual grants.
Why it's wrong here
Role-based access control ties entitlements to roles, so a temporary coverage assignment would normally be modeled as a time-bound role or an elevated request with an expiry. The scenario describes a one-off grant made directly by an owner, not a role assignment, so role derivation does not explain the persistence. Applying role logic here would not address the underlying discretionary grant.
- ✗
Access decisions are enforced by system-wide labels that owners cannot override.
Why it's wrong here
That describes mandatory access control, where sensitivity labels and clearances govern access and individual owners cannot loosen restrictions. In this hospital scenario the department head freely granted access, which is the opposite of label-based enforcement. Attributing the stale entitlement to immutable labels misidentifies the model in use and would lead to the wrong remediation approach.
- ✓
Resource owners can grant access at their own discretion, and no central authority automatically removes it.
Why this is correct
In discretionary access control the owner of a resource decides who receives access, and the system does not inherently revoke that access when the business need ends. Because the department head acted as owner and no centralized lifecycle process intervened, the permission persisted after the vacation coverage concluded. This decentralization of authority is the defining trait that produced the stale entitlement found during the audit.
- ✗
The system enforces a strict need-to-know policy using centralized administration.
Why it's wrong here
Centralized administration with strict need-to-know is characteristic of nondiscretionary or mandatory models, and it would typically include formal review and revocation. The hospital's problem is precisely the absence of centralized control, since a department head unilaterally extended access. Describing the environment as centrally administered contradicts the facts and would misdirect the audit finding.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.