Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

A hospital wants clinicians to reach patient records from any ward workstation without signing in repeatedly, but it also wants a single authoritative source of identity so that disabling an employee in the human resources system immediately removes clinical access. The identity team proposes using the Lightweight Directory Access Protocol (LDAP) as that authoritative store. Which statement best describes what LDAP provides in this design?

⚠ Common exam trap

The trap here is conflating directory services with authentication frameworks, assuming that because LDAP stores passwords it must also deliver single sign-on tokens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

LDAP is a hierarchical directory that can serve as the authoritative identity store and support authentication binds, but it does not by itself provide single sign-on or session management

The design needs an authoritative account repository plus a separate mechanism for cross-workstation session continuity. LDAP supplies the hierarchical directory and the bind operation that validates credentials, and disabling an account in that directory can take effect immediately. Single sign-on and session handling must come from an additional service, so the option that separates those responsibilities is the accurate description.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    LDAP is a hierarchical directory that can serve as the authoritative identity store and support authentication binds, but it does not by itself provide single sign-on or session management

    Why this is correct

    LDAP defines a directory information tree and operations such as bind, search, and modify, so it can hold accounts and validate credentials across the hospital. It is not a session or token service, so single sign-on across wards still requires an additional component such as Kerberos or a federation protocol layered on top of the directory.

  • ✗

    LDAP provides the ticket-granting service that lets users obtain service tickets for clinical applications

    Why it's wrong here

    Ticket granting is a function of Kerberos, whose key distribution center issues ticket-granting tickets and service tickets. LDAP is a directory access protocol and knows nothing about ticket lifecycles or renewal. A hospital could run both together, but attributing ticket issuance to LDAP misstates the protocol and would misdirect the integration effort.

  • ✗

    LDAP issues signed assertions that workstations present to each other to establish single sign-on sessions

    Why it's wrong here

    Signed assertions describing a subject and its attributes are produced by federation protocols such as SAML, not by LDAP. LDAP has no assertion or token issuance operation in its protocol definition; it performs directory lookups and binds. Claiming this capability would leave the hospital without the session mechanism it actually needs.

  • ✗

    LDAP synchronizes credentials to each workstation so that local validation removes the need for a central authority

    Why it's wrong here

    Replicating credentials to endpoints directly contradicts the requirement for one authoritative source, because revocation in the human resources system would not propagate to cached copies. LDAP clients can cache directory results, but credential replication to workstations is not an LDAP function and would create exactly the stale-access problem the hospital is trying to eliminate.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.