Courseiva
Access Controls →hardMultiple Select

SSCP Access Controls Practice Question

A security auditor is evaluating a company's implementation of mandatory access control (MAC) using a commercial trusted operating system. The auditor needs to verify that the MAC implementation correctly enforces the no read up and no write down rules for confidentiality. Which TWO of the following are essential characteristics the auditor should confirm? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse general security principles like least privilege or need-to-know with the specific label-based rules that define MAC confidentiality, overlooking that only no read up and no write down are mandatory MAC characteristics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Subjects with a lower clearance cannot read objects with a higher classification.

The no read up rule prevents subjects from reading objects with higher classifications, and the no write down rule prevents subjects from writing to objects with lower classifications. These two rules are essential for enforcing confidentiality in MAC. The auditor must confirm that subjects with lower clearance cannot read higher-classified objects and that subjects with higher clearance cannot write to lower-classified objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Users can change the classification of objects they own.

    Why it's wrong here

    In MAC, users cannot change security labels; only the system administrator or a trusted authority can assign or modify labels. Allowing users to change classifications would break the mandatory nature of MAC and could lead to unauthorized access or data leakage. Therefore, this is not a characteristic the auditor should confirm; its presence would indicate a flawed implementation.

  • ✗

    Access decisions are based on the principle of least privilege.

    Why it's wrong here

    While least privilege is a general security principle, MAC's access decisions are based on label comparison, not on least privilege per se. Least privilege is more closely associated with RBAC and ABAC. In MAC, the focus is on mandatory rules like no read up and no write down. Thus, this is not an essential characteristic to confirm for MAC's confidentiality enforcement.

  • ✓

    Subjects with a lower clearance cannot read objects with a higher classification.

    Why this is correct

    This is the no read up rule, a core principle of MAC for confidentiality. It ensures that a subject cannot access information above their clearance level, preventing unauthorized disclosure. The auditor must confirm this is enforced, as it is fundamental to MAC's confidentiality model and directly supports the no read up requirement.

  • ✗

    The system enforces a strict need-to-know policy for all users.

    Why it's wrong here

    Need-to-know is a principle often implemented alongside MAC, but it is not an inherent characteristic of MAC itself. MAC enforces label-based access, which may or may not align with need-to-know. The auditor's focus for MAC confidentiality is on the no read up and no write down rules, not on need-to-know, which is more of a policy overlay.

  • ✓

    Subjects with a higher clearance cannot write to objects with a lower classification.

    Why this is correct

    This is the no write down rule, which prevents a subject from leaking sensitive information to a lower classification level. It is essential for confidentiality in MAC, as it stops data from flowing from higher to lower sensitivity. The auditor must verify this rule is enforced to ensure the MAC implementation is sound.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.