Courseiva
Access Controls →easyMultiple Choice

SSCP Access Controls Practice Question

A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?

⚠ Common exam trap

SSCP often tests the confusion between MAC and DAC, where candidates might think that any access control based on labels is discretionary, but the key differentiator is that MAC is system-enforced and non-discretionary, while DAC allows owner discretion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is the only model where access decisions are based on comparing the subject's security clearance with the object's classification label, as defined by a central authority. In MAC, the system enforces these labels and users cannot alter them, making it mandatory rather than discretionary. This matches the scenario of assigning permissions based on clearance and classification, which are core components of MAC (e.g., Bell-LaPadula or Biba models).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-Based Access Control (RBAC)

    Why it's wrong here

    RBAC grants permissions through assigned job roles, not by comparing a subject's clearance against an object's classification label. It is tempting because RBAC efficiently manages access for large groups with stable job functions, and would be correct if permissions derived from organisational roles rather than data sensitivity levels.

  • ✗

    Discretionary Access Control (DAC)

    Why it's wrong here

    DAC grants access through object owner discretion, recorded in access control lists, with no comparison of subject clearance against object classification. The mandatory lattice of clearance and classification labels is enforced by MAC, where the system, not the owner, decides access.

  • ✗

    Attribute-Based Access Control (ABAC)

    Why it's wrong here

    ABAC evaluates attributes and policy conditions at request time, but it does not inherently enforce a mandatory clearance-versus-classification lattice. That strict hierarchical comparison is MAC's defining mechanism; ABAC would be chosen for fine-grained, context-driven policies using many attributes.

  • ✓

    Mandatory Access Control (MAC)

    Why this is correct

    Mandatory Access Control enforces access decisions through system-assigned labels: each subject holds a clearance and each object a classification, and the operating system compares these to grant or deny access. Because users cannot alter labels or delegate permissions, this satisfies the stem's requirement that permissions derive from clearance and classification rather than owner discretion.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.