SSCP Systems and Application Security Practice Question
A security administrator at a hospital is configuring a server that processes electronic health records. The server runs a Linux-based operating system, and the administrator needs to select a mandatory access control (MAC) framework that can enforce granular, policy-based restrictions on how processes interact with files, network ports, and other system resources. Which of the following should the administrator choose?
⚠ Common exam trap
The trap here is assuming that any access-control model labeled as role-based or permission-based satisfies a mandatory access control requirement, when MAC specifically requires kernel-enforced policy independent of object ownership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SELinux
SELinux provides mandatory access control by labeling subjects and objects and enforcing administrator-defined policy in the kernel, restricting processes regardless of user identity. The other choices describe authentication hardening or discretionary and role-based models that do not enforce system-wide mandatory policy. For a Linux server holding regulated health data, SELinux is the correct framework to meet the granular MAC requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password complexity and account lockout policies
Why it's wrong here
Password complexity rules and account lockout thresholds strengthen authentication but do not govern how processes access files, ports, or other resources after login. These controls address credential-guessing and brute-force risks. They do not implement mandatory access control, so they fail to meet the requirement for granular, policy-based restrictions on system interactions.
- ✗
Role-based access control (RBAC) through group membership
Why it's wrong here
Role-based access control assigns permissions based on job roles and group memberships, but on Linux it is typically layered on top of discretionary permissions. RBAC alone does not enforce a system-wide mandatory policy that constrains every process regardless of owner intent. The administrator needs kernel-level MAC, not a role-assignment model, to satisfy the requirement.
- ✗
Discretionary access control (DAC) via standard file permissions
Why it's wrong here
Standard Linux file permissions implement discretionary access control, where the file owner decides who can access a resource. DAC does not provide system-wide policy enforcement independent of user discretion, so it cannot deliver the mandatory, centralized restrictions the administrator requires. It also cannot constrain processes based on labels, making it unsuitable for the stated requirement.
- ✓
SELinux
Why this is correct
SELinux is a mandatory access control framework integrated into the Linux kernel that enforces security policies based on labels applied to processes, files, ports, and other objects. It restricts even root-level processes according to administrator-defined policy, which fits the hospital's need for granular, system-wide MAC enforcement on a Linux host handling sensitive health records.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.