SSCP Access Controls Practice Question
A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?
⚠ Common exam trap
SSCP often tests the confusion between MAC and DAC, where candidates might think that any access control based on labels is discretionary, but the key differentiator is that MAC is system-enforced and non-discretionary, while DAC allows owner discretion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mandatory Access Control (MAC)
Mandatory Access Control (MAC) is the only model where access decisions are based on comparing the subject's security clearance with the object's classification label, as defined by a central authority. In MAC, the system enforces these labels and users cannot alter them, making it mandatory rather than discretionary. This matches the scenario of assigning permissions based on clearance and classification, which are core components of MAC (e.g., Bell-LaPadula or Biba models).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
RBAC grants permissions through assigned job roles, not by comparing a subject's clearance against an object's classification label. It is tempting because RBAC efficiently manages access for large groups with stable job functions, and would be correct if permissions derived from organisational roles rather than data sensitivity levels.
- ✗
Discretionary Access Control (DAC)
Why it's wrong here
DAC grants access through object owner discretion, recorded in access control lists, with no comparison of subject clearance against object classification. The mandatory lattice of clearance and classification labels is enforced by MAC, where the system, not the owner, decides access.
- ✗
Attribute-Based Access Control (ABAC)
Why it's wrong here
ABAC evaluates attributes and policy conditions at request time, but it does not inherently enforce a mandatory clearance-versus-classification lattice. That strict hierarchical comparison is MAC's defining mechanism; ABAC would be chosen for fine-grained, context-driven policies using many attributes.
- ✓
Mandatory Access Control (MAC)
Why this is correct
Mandatory Access Control enforces access decisions through system-assigned labels: each subject holds a clearance and each object a classification, and the operating system compares these to grant or deny access. Because users cannot alter labels or delegate permissions, this satisfies the stem's requirement that permissions derive from clearance and classification rather than owner discretion.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.