SSCP Access Controls Practice Question
A security auditor is evaluating a company's implementation of mandatory access control (MAC) using a commercial trusted operating system. The auditor needs to verify that the MAC implementation correctly enforces the no read up and no write down rules for confidentiality. Which TWO of the following are essential characteristics the auditor should confirm? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse general security principles like least privilege or need-to-know with the specific label-based rules that define MAC confidentiality, overlooking that only no read up and no write down are mandatory MAC characteristics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Subjects with a lower clearance cannot read objects with a higher classification.
The no read up rule prevents subjects from reading objects with higher classifications, and the no write down rule prevents subjects from writing to objects with lower classifications. These two rules are essential for enforcing confidentiality in MAC. The auditor must confirm that subjects with lower clearance cannot read higher-classified objects and that subjects with higher clearance cannot write to lower-classified objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Users can change the classification of objects they own.
Why it's wrong here
In MAC, users cannot change security labels; only the system administrator or a trusted authority can assign or modify labels. Allowing users to change classifications would break the mandatory nature of MAC and could lead to unauthorized access or data leakage. Therefore, this is not a characteristic the auditor should confirm; its presence would indicate a flawed implementation.
- ✗
Access decisions are based on the principle of least privilege.
Why it's wrong here
While least privilege is a general security principle, MAC's access decisions are based on label comparison, not on least privilege per se. Least privilege is more closely associated with RBAC and ABAC. In MAC, the focus is on mandatory rules like no read up and no write down. Thus, this is not an essential characteristic to confirm for MAC's confidentiality enforcement.
- ✓
Subjects with a lower clearance cannot read objects with a higher classification.
Why this is correct
This is the no read up rule, a core principle of MAC for confidentiality. It ensures that a subject cannot access information above their clearance level, preventing unauthorized disclosure. The auditor must confirm this is enforced, as it is fundamental to MAC's confidentiality model and directly supports the no read up requirement.
- ✗
The system enforces a strict need-to-know policy for all users.
Why it's wrong here
Need-to-know is a principle often implemented alongside MAC, but it is not an inherent characteristic of MAC itself. MAC enforces label-based access, which may or may not align with need-to-know. The auditor's focus for MAC confidentiality is on the no read up and no write down rules, not on need-to-know, which is more of a policy overlay.
- ✓
Subjects with a higher clearance cannot write to objects with a lower classification.
Why this is correct
This is the no write down rule, which prevents a subject from leaking sensitive information to a lower classification level. It is essential for confidentiality in MAC, as it stops data from flowing from higher to lower sensitivity. The auditor must verify this rule is enforced to ensure the MAC implementation is sound.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.