SSCP Access Controls Practice Question
A security administrator is designing an access control scheme for a research lab where data sensitivity varies widely and the organization wants the operating system itself to enforce access decisions based on labels, independent of user discretion. Which TWO of the following characteristics apply to mandatory access control (MAC)? (Choose two.)
⚠ Common exam trap
The trap here is conflating discretionary owner control or role-based access with MAC, when MAC specifically removes user discretion and bases every decision on central labels and clearances.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The operating system enforces access decisions through a reference monitor
MAC is defined by centralized assignment of labels and clearances and by OS-level enforcement through a reference monitor. Users cannot alter labels or grant access at their discretion, and access is not determined by role membership. These two traits together satisfy the lab's need for label-based decisions that the operating system enforces independently of user choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Access is granted based on the user's role within the organization rather than on labels
Why it's wrong here
Granting access by role describes RBAC, which maps permissions to job functions rather than to security labels. While RBAC can complement MAC, it does not provide the label-based, centrally enforced decisions the lab requires. This option confuses two distinct models, so it does not represent a MAC characteristic.
- ✓
The operating system enforces access decisions through a reference monitor
Why this is correct
MAC depends on a reference monitor that mediates every access request and compares subject clearance against object label. This enforcement is inside the trusted computing base and cannot be bypassed by users or applications. It directly satisfies the lab's requirement that the OS itself enforce decisions based on labels, making this a core MAC characteristic alongside centralized label assignment.
- ✗
Users may change the classification label of files they own to share them more easily
Why it's wrong here
Allowing users to reclassify their own files would undermine mandatory control, since labels must be managed by the central authority. In MAC, users typically cannot alter labels, and any reclassification follows a formal, audited process. This option conflicts with the lab's requirement for OS-enforced decisions independent of user discretion, so it is incorrect.
- ✗
Resource owners can grant access at their discretion to any user they choose
Why it's wrong here
Discretionary granting by resource owners describes DAC, not MAC. In MAC, the security administrator sets labels and clearances and users cannot change them, so owner discretion is explicitly removed. This option contradicts the lab's goal of OS-enforced label-based decisions, making it incorrect. It is a common distractor because DAC and MAC are often contrasted, but the described behavior belongs to DAC.
- ✓
Access decisions are based on security labels and clearances assigned by a central authority
Why this is correct
MAC relies on labels attached to objects and clearances granted to subjects, with a central authority such as a security office defining both. The reference monitor compares these values on every access, so users cannot override decisions. This matches the lab's requirement for OS-enforced control based on labels rather than user discretion, making this a defining characteristic of MAC.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.