SSCP Access Controls Practice Question
An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?
⚠ Common exam trap
Test-takers frequently confuse RBAC with ABAC — option B looks attribute-like because it mentions 'HR' and 'Confidential', but it is a role-based rule with no Boolean combination of subject, resource, and environmental attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
If user.department == 'HR' AND doc.classification == 'Confidential' AND time.business_hours == true then permit read.
ABAC (Attribute-Based Access Control) evaluates policies built from multiple attributes — user, resource, action, and environment — combined with Boolean logic. The rule 'user.department == HR AND doc.classification == Confidential AND time.business_hours == true then permit read' explicitly combines a subject attribute (department), a resource attribute (classification), and an environmental attribute (time of day), which is the defining characteristic of an ABAC policy. NIST SP 800-162 defines ABAC as evaluating attributes of the subject, object, operation, and environment to make access decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The owner of a document can grant read access to any other user.
Why it's wrong here
Delegating access to a document owner is discretionary access control, where permissions hinge on ownership rather than evaluated attributes. It is tempting because owner-granted sharing appears in many systems, but ABAC rules must combine subject, resource and environmental attributes, such as department, classification or time, in a single policy condition.
- ✗
Users in the 'HR' role can read documents classified as 'Confidential'.
Why it's wrong here
Role-based access control evaluates a user's role, not arbitrary attributes such as department, classification or time of day. It is tempting because roles often correlate with departments, yet the stem specifies attribute-based policies, and this rule references only the HR role and a classification, omitting the attribute combinations ABAC requires.
- ✗
All users with security clearance 'Secret' can read documents labeled 'Secret'.
Why it's wrong here
This rule keys only on clearance and label, a two-attribute comparison that RBAC can express; ABAC requires evaluating multiple attributes such as department and time. It tempts because clearance-based label matching is a genuine ABAC pattern when combined with those other attributes.
- ✓
If user.department == 'HR' AND doc.classification == 'Confidential' AND time.business_hours == true then permit read.
Why this is correct
ABAC evaluates boolean rules combining multiple attributes of subject, resource, and environment. This rule matches user department, document classification, and time of day, then permits read, exactly the attribute-based evaluation model rather than role- or label-only checks.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.