SSCP Access Controls Practice Question
A security administrator is configuring access controls for a shared file server. The administrator wants to grant permissions based on the sensitivity labels of the files and the clearance levels of the users, ensuring that users cannot change these permissions. Which access control model should be implemented?
⚠ Common exam trap
The trap here is assuming that any label-based system is MAC, when in fact ABAC can also use labels as attributes but does not enforce mandatory, non-discretionary control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mandatory Access Control (MAC)
Mandatory Access Control (MAC) is the only model that enforces access using sensitivity labels on objects and clearances on subjects, with permissions managed centrally so users cannot change them. This precisely matches the administrator's requirement. The other models either rely on roles, owner discretion, or flexible attributes, none of which provide the same mandatory, label-based enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
RBAC grants access based on roles and job functions, not on sensitivity labels and clearance levels. In this scenario, the administrator needs access decisions driven by labels and clearances, which RBAC does not provide. RBAC also allows permissions to be managed through role assignments, which could be changed by administrators, contrary to the requirement that users cannot change permissions.
- ✗
Attribute-Based Access Control (ABAC)
Why it's wrong here
ABAC evaluates attributes of subjects, objects, and the environment to make access decisions. While ABAC can incorporate labels and clearances as attributes, it is not inherently non-discretionary and does not by itself prevent users from changing permissions. ABAC is more flexible but lacks the strict, label-based, mandatory enforcement characteristic of MAC.
- ✓
Mandatory Access Control (MAC)
Why this is correct
MAC enforces access based on security labels assigned to objects (files) and clearances assigned to subjects (users). These labels and clearances are typically managed by a central authority, and users cannot alter them. This matches the requirement that access be based on sensitivity labels and clearance levels, and that users cannot change permissions.
- ✗
Discretionary Access Control (DAC)
Why it's wrong here
DAC allows resource owners to set permissions at their discretion, which directly contradicts the requirement that users cannot change permissions. DAC does not use sensitivity labels or clearance levels to enforce access; it relies on owner-defined ACLs. Therefore, DAC would not satisfy the need for label-based, non-discretionary access control.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.