Courseiva
Access Controls →hardMultiple Select

SSCP Access Controls Practice Question

A security administrator is designing an access control scheme for a research lab where data sensitivity varies widely and the organization wants the operating system itself to enforce access decisions based on labels, independent of user discretion. Which TWO of the following characteristics apply to mandatory access control (MAC)? (Choose two.)

⚠ Common exam trap

The trap here is conflating discretionary owner control or role-based access with MAC, when MAC specifically removes user discretion and bases every decision on central labels and clearances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The operating system enforces access decisions through a reference monitor

MAC is defined by centralized assignment of labels and clearances and by OS-level enforcement through a reference monitor. Users cannot alter labels or grant access at their discretion, and access is not determined by role membership. These two traits together satisfy the lab's need for label-based decisions that the operating system enforces independently of user choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Access is granted based on the user's role within the organization rather than on labels

    Why it's wrong here

    Granting access by role describes RBAC, which maps permissions to job functions rather than to security labels. While RBAC can complement MAC, it does not provide the label-based, centrally enforced decisions the lab requires. This option confuses two distinct models, so it does not represent a MAC characteristic.

  • ✓

    The operating system enforces access decisions through a reference monitor

    Why this is correct

    MAC depends on a reference monitor that mediates every access request and compares subject clearance against object label. This enforcement is inside the trusted computing base and cannot be bypassed by users or applications. It directly satisfies the lab's requirement that the OS itself enforce decisions based on labels, making this a core MAC characteristic alongside centralized label assignment.

  • ✗

    Users may change the classification label of files they own to share them more easily

    Why it's wrong here

    Allowing users to reclassify their own files would undermine mandatory control, since labels must be managed by the central authority. In MAC, users typically cannot alter labels, and any reclassification follows a formal, audited process. This option conflicts with the lab's requirement for OS-enforced decisions independent of user discretion, so it is incorrect.

  • ✗

    Resource owners can grant access at their discretion to any user they choose

    Why it's wrong here

    Discretionary granting by resource owners describes DAC, not MAC. In MAC, the security administrator sets labels and clearances and users cannot change them, so owner discretion is explicitly removed. This option contradicts the lab's goal of OS-enforced label-based decisions, making it incorrect. It is a common distractor because DAC and MAC are often contrasted, but the described behavior belongs to DAC.

  • ✓

    Access decisions are based on security labels and clearances assigned by a central authority

    Why this is correct

    MAC relies on labels attached to objects and clearances granted to subjects, with a central authority such as a security office defining both. The reference monitor compares these values on every access, so users cannot override decisions. This matches the lab's requirement for OS-enforced control based on labels rather than user discretion, making this a defining characteristic of MAC.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.