SSCP Systems and Application Security Practice Question
An organization uses Linux servers and wants to implement mandatory access control (MAC) to enhance security. Which TWO technologies can be used? (Select TWO.)
⚠ Common exam trap
SSCP often tests the distinction between MAC frameworks (SELinux, AppArmor) and adjacent security tools (iptables for firewalling, auditd for auditing, PAM for authentication) — candidates pick familiar tools without confirming they enforce MAC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SELinux
SELinux (A) is correct because it is a Linux kernel security module that enforces mandatory access control by applying type enforcement, role-based access control, and multi-level security policies that confine processes and users regardless of their discretionary permissions. AppArmor (C) is also correct because it implements MAC through per-program profiles that restrict an application's file, network, and capability access using path-based rules loaded into the kernel. iptables (B) is incorrect because it is a packet-filtering firewall tool for network traffic, not a MAC framework for constraining process privileges. auditd (D) is incorrect because it is the Linux auditing daemon that logs security-relevant events, providing accountability rather than access enforcement. PAM (E) is incorrect because it is an authentication framework that handles login and credential checks, not a mandatory access control mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SELinux
Why this is correct
SELinux enforces mandatory access control through kernel-level type enforcement and security contexts, applying policy defined by the administrator rather than the resource owner. This satisfies the Linux MAC requirement because even root processes are confined by the loaded policy.
- ✗
iptables
Why it's wrong here
iptables filters network packets by address, port and protocol; it enforces no per-process or per-file label policy. It is tempting because iptables is the default Linux host firewall, and would be correct where the requirement is restricting inbound and outbound network traffic.
- ✓
AppArmor
Why this is correct
AppArmor implements mandatory access control on Linux by confining programs to per-profile path-based rules loaded into the kernel. Unlike discretionary permissions, these profiles are administrator-defined and cannot be overridden by users, satisfying the MAC requirement on Linux servers.
- ✗
auditd
Why it's wrong here
auditd logs system calls and file events for accountability; it observes activity rather than enforcing access decisions. It is tempting because audit trails underpin compliance and intrusion detection, and would be correct where the requirement is recording security-relevant events for later review.
- ✗
PAM (Pluggable Authentication Modules)
Why it's wrong here
PAM handles authentication and session modules, not kernel-enforced access labels on subjects and objects. It is tempting because PAM centralises Linux authentication policy, and would be correct where the requirement is pluggable login, password and account-control configuration.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.