Courseiva
easyMultiple Choice

SSCP Practice Question: A security policy requires that all access to…

A security policy requires that all access to sensitive data be logged. Which access control function does this support?

⚠ Common exam trap

It's easy for candidates to confuse Authorization (which controls access) with Accounting (which records access), mistakenly thinking that setting permissions automatically logs access, when in fact logging requires a separate audit configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accounting

The requirement to log all access to sensitive data directly supports the Accounting (auditing) function of access controls. Accounting tracks user activities and resource usage, providing an audit trail that can be reviewed for compliance, security incidents, and policy enforcement. This is distinct from Authentication (verifying identity) and Authorization (granting permissions), which do not inherently produce logs of access events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authentication

    Why it's wrong here

    Authentication verifies a subject's claimed identity before access is granted; it produces no record of resource access. Logging every access to sensitive data is an accountability function, which records and traces activity. Authentication would be the answer if the policy demanded proof of identity at sign-in.

  • ✗

    Authorization

    Why it's wrong here

    Authorization decides whether an authenticated subject may access a resource, but the decision itself is not the logging. Accountability is the function that records and traces access to sensitive data. Authorization would be correct if the policy required restricting access by role or permission.

  • ✓

    Accounting

    Why this is correct

    Accounting records and logs user activity, including access to sensitive data, so it directly satisfies the policy requiring all such access to be logged. Authentication verifies identity and authorisation grants rights; only accounting provides the audit trail.

  • ✗

    Provisioning

    Why it's wrong here

    Provisioning creates, modifies and deletes user accounts and their entitlements; it does not record access events. Logging sensitive-data access is the auditing function, which captures who accessed what and when. Provisioning would be the right answer if the policy required automated account creation or timely removal of access for joiners and leavers.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.