Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?

⚠ Common exam trap

SSCP often tests the confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up) — candidates who memorize only one direction of the rules pick the wrong model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MAC with Bell-LaPadula model

The Bell-LaPadula model is a mandatory access control (MAC) model focused on confidentiality. Its two core rules are the Simple Security Property (no read up: a subject can only read objects at or below its clearance) and the Star Property (no write down: a subject can only write to objects at or above its clearance). The scenario describes exactly these two rules, so MAC with Bell-LaPadula is the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    MAC with Bell-LaPadula model

    Why this is correct

    Bell-LaPadula enforces mandatory access control through the no-read-up and no-write-down rules, matching the stated label comparisons exactly. Sensitivity labels on subjects and objects, rather than owner discretion, make the model mandatory, satisfying both the read and write constraints described.

  • ✗

    MAC with Biba model

    Why it's wrong here

    Biba enforces integrity, permitting reads of equal or higher integrity and writes to equal or lower integrity — the inverse of the stated rules. It is tempting because it also uses labels, but it would be correct for preventing integrity contamination, not the confidentiality policy described.

  • ✗

    DAC with owner-based permissions

    Why it's wrong here

    DAC grants access through object-owner discretion, not sensitivity labels compared against clearance levels. It is tempting because owners can still assign permissions, but it would be correct where flexible, owner-controlled sharing is required rather than the mandatory lattice rules described.

  • ✗

    RBAC with role hierarchy

    Why it's wrong here

    RBAC assigns permissions through roles and hierarchy, not through comparing subject clearance against object sensitivity labels. It is tempting because roles simplify administration, but it would be correct where job-function-based access is required rather than the mandatory label comparison described.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.