Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?

⚠ Common exam trap

Test-takers frequently confuse RBAC with ABAC — option B looks attribute-like because it mentions 'HR' and 'Confidential', but it is a role-based rule with no Boolean combination of subject, resource, and environmental attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

If user.department == 'HR' AND doc.classification == 'Confidential' AND time.business_hours == true then permit read.

ABAC (Attribute-Based Access Control) evaluates policies built from multiple attributes — user, resource, action, and environment — combined with Boolean logic. The rule 'user.department == HR AND doc.classification == Confidential AND time.business_hours == true then permit read' explicitly combines a subject attribute (department), a resource attribute (classification), and an environmental attribute (time of day), which is the defining characteristic of an ABAC policy. NIST SP 800-162 defines ABAC as evaluating attributes of the subject, object, operation, and environment to make access decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The owner of a document can grant read access to any other user.

    Why it's wrong here

    Delegating access to a document owner is discretionary access control, where permissions hinge on ownership rather than evaluated attributes. It is tempting because owner-granted sharing appears in many systems, but ABAC rules must combine subject, resource and environmental attributes, such as department, classification or time, in a single policy condition.

  • ✗

    Users in the 'HR' role can read documents classified as 'Confidential'.

    Why it's wrong here

    Role-based access control evaluates a user's role, not arbitrary attributes such as department, classification or time of day. It is tempting because roles often correlate with departments, yet the stem specifies attribute-based policies, and this rule references only the HR role and a classification, omitting the attribute combinations ABAC requires.

  • ✗

    All users with security clearance 'Secret' can read documents labeled 'Secret'.

    Why it's wrong here

    This rule keys only on clearance and label, a two-attribute comparison that RBAC can express; ABAC requires evaluating multiple attributes such as department and time. It tempts because clearance-based label matching is a genuine ABAC pattern when combined with those other attributes.

  • ✓

    If user.department == 'HR' AND doc.classification == 'Confidential' AND time.business_hours == true then permit read.

    Why this is correct

    ABAC evaluates boolean rules combining multiple attributes of subject, resource, and environment. This rule matches user department, document classification, and time of day, then permits read, exactly the attribute-based evaluation model rather than role- or label-only checks.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.