SSCP Access Controls Practice Question
A security administrator is implementing a biometric access control system for a data center. The organization wants to minimize the chance that an unauthorized person is granted access, even if it means legitimate users occasionally have to retry. Which metric should the administrator tune to achieve this goal?
⚠ Common exam trap
Watch out — candidates often confuse FAR with FRR, or assuming that CER/EER is always the optimal setting, when the scenario explicitly prioritizes security over convenience.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
False Acceptance Rate (FAR)
The goal is to minimize unauthorized access, which means reducing the False Acceptance Rate. Lowering FAR makes the system stricter, accepting fewer impostors, though it may increase false rejections. CER and EER represent balanced points and do not prioritize security, while FRR relates to rejecting legitimate users, which is not the primary concern here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Crossover Error Rate (CER)
Why it's wrong here
CER is the point where FAR and FRR are equal, representing the overall accuracy of a biometric system. While it is useful for comparing systems, tuning to the CER does not specifically minimize unauthorized access; it balances both error types. The requirement prioritizes security over convenience, so the administrator should not aim for the CER but rather for a lower FAR.
- ✓
False Acceptance Rate (FAR)
Why this is correct
FAR measures the likelihood that an unauthorized user is incorrectly accepted. By tuning the system to lower the FAR, the administrator reduces the chance of granting access to impostors. This aligns with the goal of minimizing unauthorized access, even at the cost of more frequent retries by legitimate users, which would increase the False Rejection Rate.
- ✗
False Rejection Rate (FRR)
Why it's wrong here
FRR measures the likelihood that an authorized user is incorrectly rejected. Lowering FRR would reduce legitimate user retries but would not minimize unauthorized access. In fact, tightening the system to lower FAR typically increases FRR. Since the goal is to prevent unauthorized access, focusing on FRR is the opposite of what is needed.
- ✗
Equal Error Rate (EER)
Why it's wrong here
EER is another term for the crossover error rate, where FAR equals FRR. Like CER, it represents a balanced operating point rather than a security-focused one. Tuning to EER would not minimize the chance of unauthorized access; it would equalize both error types. The scenario calls for prioritizing security, so EER is not the appropriate target.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.