Courseiva

SSCP Systems and Application Security Practice Question

A security administrator at a hospital is configuring a server that processes electronic health records. The server runs a Linux-based operating system, and the administrator needs to select a mandatory access control (MAC) framework that can enforce granular, policy-based restrictions on how processes interact with files, network ports, and other system resources. Which of the following should the administrator choose?

⚠ Common exam trap

The trap here is assuming that any access-control model labeled as role-based or permission-based satisfies a mandatory access control requirement, when MAC specifically requires kernel-enforced policy independent of object ownership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SELinux

SELinux provides mandatory access control by labeling subjects and objects and enforcing administrator-defined policy in the kernel, restricting processes regardless of user identity. The other choices describe authentication hardening or discretionary and role-based models that do not enforce system-wide mandatory policy. For a Linux server holding regulated health data, SELinux is the correct framework to meet the granular MAC requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password complexity and account lockout policies

    Why it's wrong here

    Password complexity rules and account lockout thresholds strengthen authentication but do not govern how processes access files, ports, or other resources after login. These controls address credential-guessing and brute-force risks. They do not implement mandatory access control, so they fail to meet the requirement for granular, policy-based restrictions on system interactions.

  • ✗

    Role-based access control (RBAC) through group membership

    Why it's wrong here

    Role-based access control assigns permissions based on job roles and group memberships, but on Linux it is typically layered on top of discretionary permissions. RBAC alone does not enforce a system-wide mandatory policy that constrains every process regardless of owner intent. The administrator needs kernel-level MAC, not a role-assignment model, to satisfy the requirement.

  • ✗

    Discretionary access control (DAC) via standard file permissions

    Why it's wrong here

    Standard Linux file permissions implement discretionary access control, where the file owner decides who can access a resource. DAC does not provide system-wide policy enforcement independent of user discretion, so it cannot deliver the mandatory, centralized restrictions the administrator requires. It also cannot constrain processes based on labels, making it unsuitable for the stated requirement.

  • ✓

    SELinux

    Why this is correct

    SELinux is a mandatory access control framework integrated into the Linux kernel that enforces security policies based on labels applied to processes, files, ports, and other objects. It restricts even root-level processes according to administrator-defined policy, which fits the hospital's need for granular, system-wide MAC enforcement on a Linux host handling sensitive health records.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.