Courseiva

SSCP Systems and Application Security Practice Question

An organization uses Linux servers and wants to implement mandatory access control (MAC) to enhance security. Which TWO technologies can be used? (Select TWO.)

⚠ Common exam trap

SSCP often tests the distinction between MAC frameworks (SELinux, AppArmor) and adjacent security tools (iptables for firewalling, auditd for auditing, PAM for authentication) — candidates pick familiar tools without confirming they enforce MAC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SELinux

SELinux (A) is correct because it is a Linux kernel security module that enforces mandatory access control by applying type enforcement, role-based access control, and multi-level security policies that confine processes and users regardless of their discretionary permissions. AppArmor (C) is also correct because it implements MAC through per-program profiles that restrict an application's file, network, and capability access using path-based rules loaded into the kernel. iptables (B) is incorrect because it is a packet-filtering firewall tool for network traffic, not a MAC framework for constraining process privileges. auditd (D) is incorrect because it is the Linux auditing daemon that logs security-relevant events, providing accountability rather than access enforcement. PAM (E) is incorrect because it is an authentication framework that handles login and credential checks, not a mandatory access control mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SELinux

    Why this is correct

    SELinux enforces mandatory access control through kernel-level type enforcement and security contexts, applying policy defined by the administrator rather than the resource owner. This satisfies the Linux MAC requirement because even root processes are confined by the loaded policy.

  • ✗

    iptables

    Why it's wrong here

    iptables filters network packets by address, port and protocol; it enforces no per-process or per-file label policy. It is tempting because iptables is the default Linux host firewall, and would be correct where the requirement is restricting inbound and outbound network traffic.

  • ✓

    AppArmor

    Why this is correct

    AppArmor implements mandatory access control on Linux by confining programs to per-profile path-based rules loaded into the kernel. Unlike discretionary permissions, these profiles are administrator-defined and cannot be overridden by users, satisfying the MAC requirement on Linux servers.

  • ✗

    auditd

    Why it's wrong here

    auditd logs system calls and file events for accountability; it observes activity rather than enforcing access decisions. It is tempting because audit trails underpin compliance and intrusion detection, and would be correct where the requirement is recording security-relevant events for later review.

  • ✗

    PAM (Pluggable Authentication Modules)

    Why it's wrong here

    PAM handles authentication and session modules, not kernel-enforced access labels on subjects and objects. It is tempting because PAM centralises Linux authentication policy, and would be correct where the requirement is pluggable login, password and account-control configuration.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.