SSCP · domain
Access Controls
Access Controls covers how subjects are identified, authenticated, authorized, and deprovisioned across the account lifecycle. SSCP questions test model selection (MAC, DAC, RBAC, ABAC), authentication factors and one-time passwords, least privilege, separation of duties, and the correct order of termination actions such as disabling accounts before removing access.
Focused practice
Practice Access Controls questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Access Controls
Be able to map a scenario to the right access control model, authentication factor, or lifecycle step, and state the action order. The single most important thing: on termination, disable the account first, then remove or transfer access and data before deletion.
Distinguishing MAC, DAC, RBAC, and ABAC based on how permissions are assigned
Selecting authentication factors: something you know, have, or are
Ordering account lifecycle steps: provisioning, review, and deprovisioning on termination
Applying least privilege, need to know, and separation of duties controls
Watch out for
Common Access Controls exam traps
- ▸Confusing MAC with DAC: MAC uses labels and clearances, while DAC lets the object owner set permissions.
- ▸Deleting a terminated user's account before disabling it, losing audit trail and risking residual access.
- ▸Treating RBAC as clearance-based; RBAC assigns permissions through roles, not subject clearance versus object classification.
Question index
All Access Controls questions (100)
Click any question to see the full explanation, or start a practice session above.
An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?
Hard2A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?
Medium3A company implements a password policy requiring a minimum length of 12 characters, including uppercase, lowercase, digits, and special characters. Passwords must be changed every 90 days, and the last 10 passwords cannot be reused. After a brute-force attack, several accounts were compromised despite the policy. Which additional control would most effectively mitigate such attacks?
Hard4A security team is designing an access control system for a research facility. They need a model that supports fine-grained, dynamic access decisions based on user department, project assignment, time of day, and the sensitivity of the resource. The model must also allow policies to be expressed in a human-readable language and evaluated at runtime. Which access control model best fits these requirements?
Hard5An organization uses ABAC to control access to a document. Which attribute combination would be used to allow access only during business hours from a managed device?
Hard6A security administrator is configuring a Linux server that hosts a shared project directory. The requirement is that new files created in the directory /projects/team must automatically inherit the group owner of the parent directory rather than the primary group of the user who created them. The administrator wants the setting to apply only to that directory. Which command should the administrator use?
Medium7An organization is implementing multi-factor authentication (MFA). Which TWO of the following are examples of something you have?
Medium8During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?
Hard9A security team is reviewing access control models for a new document management system. The system must support discretionary sharing where document owners can grant access to other users, but it must also enforce a mandatory rule that any document labeled 'Confidential' cannot be accessed by users without a 'Confidential' clearance, regardless of owner intent. Which access control model best satisfies both requirements?
Hard10Which access control model allows the owner of a resource to grant permissions to others?
Easy11An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?
Hard12A hospital uses a MAC-based system where data labels carry classifications such as Restricted and Public, and user clearances are assigned by the security office. A nurse with a Secret-equivalent clearance attempts to read a patient record labeled with a higher classification. According to the Bell-LaPadula model, what should occur?
Hard13An organization is reviewing its account lifecycle management process. Which TWO activities are part of the provisioning phase? (Select TWO.)
Medium14In a Kerberos environment, what is the primary function of the Ticket Granting Ticket (TGT)?
Medium15A security administrator is configuring a network access control deployment that must authenticate employee laptops before they receive an IP address on the corporate VLAN. The administrator wants to use the IEEE 802.1X framework. Which two components are required for this framework to function? (Choose two.)
Medium16An organization uses OAuth 2.0 for delegated access to a cloud storage API. A third-party application requests an access token to read user files. What is the primary purpose of the access token in OAuth?
Medium17A security analyst is reviewing access controls for a database server. The database administrator has granted all users in the 'sales' role SELECT, INSERT, UPDATE, and DELETE permissions on the 'orders' table. Which access control principle is being violated?
Medium18A security consultant is reviewing an organization's identity and access management (IAM) architecture. The organization wants to implement a system where users can authenticate once and access multiple independent systems without re-entering credentials, while also enabling centralized session termination. Which TWO of the following are appropriate components or protocols to meet these requirements? (Choose two.)
Hard19A small business wants to implement single sign-on so employees can authenticate once and reach several internal web applications without re-entering credentials. The applications support SAML 2.0. Which component issues the signed assertion that the applications consume to establish the user's identity?
Easy20A company is implementing a new access control system and wants to ensure that users are granted only the minimum permissions necessary to perform their job functions. Which principle is being applied?
Medium21A biometric system has a high false rejection rate (FRR). Which of the following is a likely consequence?
Medium22Which term describes the process of verifying the identity of a user, system, or entity?
Easy23A hospital wants clinicians to reach patient records from any ward workstation without signing in repeatedly, but it also wants a single authoritative source of identity so that disabling an employee in the human resources system immediately removes clinical access. The identity team proposes using the Lightweight Directory Access Protocol (LDAP) as that authoritative store. Which statement best describes what LDAP provides in this design?
Hard24Which access control model enforces the principle of least privilege by granting permissions based on job functions and requires separation of duties?
Easy25A security administrator needs to implement an access control model that grants access based on attributes of the user, resource, and environment, using policy rules. Which model is most appropriate?
Medium26Which of the following is a common method for implementing multi-factor authentication (MFA) using something you have and something you know?
Easy27In the Bell-LaPadula model, which property prevents a subject from reading an object at a higher classification level?
Medium28A retail chain issues each cashier a badge containing a photograph and a scannable code. At the start of every shift, a supervisor visually compares the badge photograph to the person and scans the code into the point-of-sale terminal. Which two access control components are being combined in this process?
Easy29An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?
Medium30A financial services firm is deploying a centralized access control server that will make authorization decisions for dozens of internal applications. The architects want the applications to query a single decision point instead of embedding their own permission logic. Which two characteristics should the chosen model exhibit? (Choose two.)
Medium31In an OAuth 2.0 authorization flow, a client application receives an access token. This token is used to:
Hard32In a biometric system, the point at which the false rejection rate (FRR) equals the false acceptance rate (FAR) is known as the:
Hard33A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?
Medium34Which access control model enforces security based on classification labels assigned to subjects and objects, commonly used for confidentiality?
Easy35An organization implements a policy requiring passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 60 days. Which password policy elements are being enforced?
Medium36A healthcare organization deploys a new electronic records system. Clinicians may access patient records only while assigned to the cardiology department, and access is automatically revoked when they rotate to oncology. Which access control model best supports this requirement?
Hard37A retail company issues contactless smart cards to employees for physical entry to its data center. The security manager wants to ensure that a lost card cannot be used by someone who finds it, without adding a fingerprint reader at every door. Which access control enhancement best meets this requirement?
Easy38A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?
Medium39A security administrator is configuring a new system and wants to enforce a mandatory access control model to ensure confidentiality of classified data. Which access control model should the administrator implement?
Medium40A hospital is deploying a new electronic health records (EHR) system. The security team wants to ensure that access decisions are based on the user's assigned job function rather than on the user's identity or resource ownership. Which access control model best meets this requirement?
Medium41An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?
Medium42What is the primary risk associated with service accounts in an enterprise?
Medium43A financial firm is designing access controls for a trading application. The firm wants to prevent any single employee from both initiating a large funds transfer and approving it, and it also wants to ensure that access rights are automatically revoked when an employee changes departments. Which combination of principles is the firm applying?
Hard44A financial institution uses a centralized authentication system. An auditor notes that when an employee is terminated, their access to several critical applications remains active for up to 24 hours because each application maintains its own local user database. Which of the following is the MOST effective control to reduce this window of exposure?
Hard45Which authentication method generates a one-time password that is valid for only a short time window?
Easy46A software company wants outside contractors to reach a single internal source code repository without creating accounts in the company directory. The identity team proposes using the Security Assertion Markup Language so that contractors authenticate against their own employer's identity provider. Which statement describes the trust relationship that must exist for this to work?
Medium47In a Bell-LaPadula model implementation, a user with a Secret clearance attempts to read a document classified as Top Secret. Additionally, they try to write to a document classified as Unclassified. What are the results of these actions?
Hard48A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?
Easy49Which access control model allows the owner of a resource to grant access permissions to other users?
Easy50A security administrator is implementing a biometric access control system for a data center. The organization wants to minimize the chance that an unauthorized person is granted access, even if it means legitimate users occasionally have to retry. Which metric should the administrator tune to achieve this goal?
Medium51A healthcare organization uses a mandatory access control (MAC) system to protect patient records. A nurse with a Secret clearance attempts to access a file classified as Top Secret. According to the Bell-LaPadula model, what will happen?
Medium52What is the primary purpose of a Privileged Access Management (PAM) solution?
Easy53A small business wants employees to authenticate to the corporate VPN using a hardware token that generates a time-based one-time code in addition to their password. Which authentication factor category does the hardware token represent?
Easy54What is the primary purpose of account deprovisioning?
Easy55What is the primary purpose of account deprovisioning in the account lifecycle?
Easy56An organization requires users to authenticate using a password and a one-time code from a mobile app. Which authentication method is being used?
Easy57A company is implementing single sign-on (SSO) for its internal applications. Which TWO of the following protocols are commonly used for SSO?
Medium58An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?
Medium59A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?
Medium60During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?
Hard61A security administrator is designing an access control scheme for a research lab where data sensitivity varies widely and the organization wants the operating system itself to enforce access decisions based on labels, independent of user discretion. Which TWO of the following characteristics apply to mandatory access control (MAC)? (Choose two.)
Hard62Which TWO of the following are characteristics of the Biba integrity model? (Choose TWO.)
Medium63A security administrator is configuring access controls for a shared file server. The administrator wants to grant permissions based on the sensitivity labels of the files and the clearance levels of the users, ensuring that users cannot change these permissions. Which access control model should be implemented?
Easy64A financial services firm wants to let customers authorize a third-party budgeting application to read their account transaction history without sharing their banking password. Which technology should the firm deploy?
Medium65A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?
Easy66A company is implementing a biometric authentication system for physical access to a data center. The system must minimize false acceptances. Which metric is most directly related to false acceptance rate (FAR)?
Medium67A small business owner wants to implement access control for a shared file server. The owner wants each department manager to be able to decide which of their employees can access specific folders, without involving the IT department for every change. Which access control model is most appropriate for this requirement?
Easy68A security administrator at a financial firm is configuring access control for a new document management system. The system must enforce access decisions based on the sensitivity labels of documents and the clearance levels of employees, and it must prevent users from delegating their access to others. Which access control model should the administrator implement?
Medium69A company deploys a RADIUS server for wireless 802.1X authentication. Users report that after a password change, their devices still authenticate successfully for several hours using cached credentials. Which RADIUS behavior most likely explains this?
Medium70An Identity Provider (IdP) sends an XML-based assertion to a Service Provider (SP) to grant access. Which federated identity standard is being used?
Medium71A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)
Hard72A security auditor is evaluating a company's implementation of mandatory access control (MAC) using a commercial trusted operating system. The auditor needs to verify that the MAC implementation correctly enforces the no read up and no write down rules for confidentiality. Which TWO of the following are essential characteristics the auditor should confirm? (Choose two.)
Hard73In a federated identity scenario, a user authenticates to their home domain and accesses a resource in a partner domain. The partner domain trusts the authentication performed by the home domain. What is the home domain's role in this trust relationship?
Hard74An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?
Medium75A defense contractor runs an air-gapped laboratory where removable media are used to move engineering data between isolated enclaves. Policy requires that a workstation be usable only when a specific approved removable device is inserted, and that the workstation become unusable the instant that device is removed. Which access control approach best enforces this behavior?
Hard76An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?
Hard77A financial institution uses a RADIUS server for centralized authentication of its VPN users. A security administrator notices that authentication requests from a new VPN concentrator are being rejected, while requests from other devices work fine. The RADIUS server logs show that the shared secret does not match. What is the most likely cause?
Hard78An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?
Medium79A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?
Medium80An organization is implementing a password policy that requires passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 90 days. Additionally, users cannot reuse any of the last 10 passwords. Which password policy element does the last requirement address?
Hard81A user claims to be 'jsmith' and provides a password. What is the term for the step where the system verifies that the password matches the one on file for 'jsmith'?
Medium82Which of the following is the correct order of the access control process?
Easy83A healthcare organization must enforce access control based on a combination of the user's assigned department, the classification of the data being accessed, and the time of day. Users in the cardiology department may view patient records only during their scheduled shift, and only if the record belongs to a patient currently admitted to cardiology. Which access control model BEST supports these requirements?
Medium84Which access control model allows the owner of a resource to determine who can access it and what permissions they have?
Medium85A security analyst is reviewing authentication logs and notices that a user account was used to log in from two different geographic locations within a five-minute window. The organization uses a centralized RADIUS server for authentication. Which of the following should the analyst investigate FIRST to determine if this is a legitimate concurrent session or a compromise?
Easy86A security team is hardening a centralized authentication service and wants to reduce the risk of credential replay and lateral movement if a password is compromised. Which TWO of the following controls directly support this goal? (Choose two.)
Medium87In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?
Hard88An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)
Hard89An IT administrator needs to deprovision a user who has been terminated. Which of the following actions should be performed first to ensure security?
Medium90An organization uses Kerberos for single sign-on. When a user logs in, they receive a Ticket Granting Ticket (TGT). What is the primary purpose of the TGT?
Medium91Which of the following best describes the concept of accountability in access controls?
Medium92A security architect is designing an access control system for a healthcare application. The system must ensure that a nurse can view patient records but cannot modify them, and that a doctor can both view and update records. Additionally, the system must prevent a single user from both ordering a medication and approving its administration. Which TWO access control principles are being applied? (Select TWO.)
Medium93An organization is implementing a privileged access management (PAM) solution. Which THREE of the following are common PAM capabilities?
Medium94A hospital uses a discretionary access control model on its file shares. A department head grants a colleague read access to a folder containing protected health information so they can cover a vacation. Months later an audit finds the access still active after the coverage ended. Which characteristic of discretionary access control most directly explains why this happened?
Hard95A company uses discretionary access control (DAC) for its file shares. A project manager creates a folder and wants to grant a team member read-only access. Which of the following best describes how access is determined in this model?
Medium96Which access control model allows the owner of a resource to determine who can access it and what privileges they have?
Easy97A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?
Easy98An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?
Hard99Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?
Medium100A small business owner wants to implement access control for a shared folder on a Windows server. The owner wants to grant different permissions to individual employees based on their specific job duties, without creating groups. Which access control model is most appropriate?
EasyOther domains
All SSCP exam domains
Frequently asked questions
- What does the Access Controls domain cover on the SSCP exam?
- Be able to map a scenario to the right access control model, authentication factor, or lifecycle step, and state the action order. The single most important thing: on termination, disable the account first, then remove or transfer access and data before deletion.
- How many questions are in this domain?
- This page lists all 100 Access Controls questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Access Controls questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.