Courseiva
Access Controls →easyMultiple Choice

SSCP Access Controls Practice Question

A security administrator is configuring access controls for a shared file server. The administrator wants to grant permissions based on the sensitivity labels of the files and the clearance levels of the users, ensuring that users cannot change these permissions. Which access control model should be implemented?

⚠ Common exam trap

The trap here is assuming that any label-based system is MAC, when in fact ABAC can also use labels as attributes but does not enforce mandatory, non-discretionary control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is the only model that enforces access using sensitivity labels on objects and clearances on subjects, with permissions managed centrally so users cannot change them. This precisely matches the administrator's requirement. The other models either rely on roles, owner discretion, or flexible attributes, none of which provide the same mandatory, label-based enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-Based Access Control (RBAC)

    Why it's wrong here

    RBAC grants access based on roles and job functions, not on sensitivity labels and clearance levels. In this scenario, the administrator needs access decisions driven by labels and clearances, which RBAC does not provide. RBAC also allows permissions to be managed through role assignments, which could be changed by administrators, contrary to the requirement that users cannot change permissions.

  • ✗

    Attribute-Based Access Control (ABAC)

    Why it's wrong here

    ABAC evaluates attributes of subjects, objects, and the environment to make access decisions. While ABAC can incorporate labels and clearances as attributes, it is not inherently non-discretionary and does not by itself prevent users from changing permissions. ABAC is more flexible but lacks the strict, label-based, mandatory enforcement characteristic of MAC.

  • ✓

    Mandatory Access Control (MAC)

    Why this is correct

    MAC enforces access based on security labels assigned to objects (files) and clearances assigned to subjects (users). These labels and clearances are typically managed by a central authority, and users cannot alter them. This matches the requirement that access be based on sensitivity labels and clearance levels, and that users cannot change permissions.

  • ✗

    Discretionary Access Control (DAC)

    Why it's wrong here

    DAC allows resource owners to set permissions at their discretion, which directly contradicts the requirement that users cannot change permissions. DAC does not use sensitivity labels or clearance levels to enforce access; it relies on owner-defined ACLs. Therefore, DAC would not satisfy the need for label-based, non-discretionary access control.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.