Courseiva

SSCP · domain

Access Controls

Practise Systems Security Certified Practitioner SSCP Access Controls practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

80 questions18 easy39 medium23 hard

Focused practice

Practice Access Controls questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Access Controls

Access Controls questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Access Controls exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Access Controls questions (80)

Click any question to see the full explanation, or start a practice session above.

1

An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?

Hard
2

A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?

Medium
3

A company implements a password policy requiring a minimum length of 12 characters, including uppercase, lowercase, digits, and special characters. Passwords must be changed every 90 days, and the last 10 passwords cannot be reused. After a brute-force attack, several accounts were compromised despite the policy. Which additional control would most effectively mitigate such attacks?

Hard
4

An organization uses ABAC to control access to a document. Which attribute combination would be used to allow access only during business hours from a managed device?

Hard
5

An organization is implementing multi-factor authentication (MFA). Which TWO of the following are examples of something you have?

Medium
6

During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?

Hard
7

Which access control model allows the owner of a resource to grant permissions to others?

Easy
8

An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?

Hard
9

An organization is reviewing its account lifecycle management process. Which TWO activities are part of the provisioning phase? (Select TWO.)

Medium
10

In a Kerberos environment, what is the primary function of the Ticket Granting Ticket (TGT)?

Medium
11

A security analyst notices that a user's account was used to access sensitive files after the user had left the company. Which access control principle was most likely violated?

Hard
12

An organization implements RBAC to enforce separation of duties. Which of the following is a key benefit of using role-based access control in this context?

Medium
13

An organization uses OAuth 2.0 for delegated access to a cloud storage API. A third-party application requests an access token to read user files. What is the primary purpose of the access token in OAuth?

Medium
14

A company wants to implement multi-factor authentication (MFA) for remote access. Which THREE of the following are examples of different authentication factors? (Choose THREE.)

Medium
15

A security engineer is designing a federated identity solution for cross-domain authentication. Which THREE of the following technologies are commonly used?

Hard
16

A security administrator is configuring a system to enforce separation of duties. In which access control model is this principle most directly implemented?

Medium
17

A security analyst is reviewing access controls for a database server. The database administrator has granted all users in the 'sales' role SELECT, INSERT, UPDATE, and DELETE permissions on the 'orders' table. Which access control principle is being violated?

Medium
18

A biometric system has a high false rejection rate (FRR). Which of the following is a likely consequence?

Medium
19

During a security audit, it is discovered that a service account has been used to log in interactively to a server. The account was originally provisioned only for running a background service. Which PAM (Privileged Access Management) control would best prevent such misuse in the future?

Hard
20

Which term describes the process of verifying the identity of a user, system, or entity?

Easy
21

Which access control model enforces the principle of least privilege by granting permissions based on job functions and requires separation of duties?

Easy
22

A security administrator needs to implement an access control model that grants access based on attributes of the user, resource, and environment, using policy rules. Which model is most appropriate?

Medium
23

Which of the following is a common method for implementing multi-factor authentication (MFA) using something you have and something you know?

Easy
24

In the Bell-LaPadula model, which property prevents a subject from reading an object at a higher classification level?

Medium
25

A security analyst is investigating an account compromise. The organization uses Kerberos for single sign-on. Which TWO of the following would help in tracking the source of the compromise?

Hard
26

An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?

Medium
27

In an OAuth 2.0 authorization flow, a client application receives an access token. This token is used to:

Hard
28

In a biometric system, the point at which the false rejection rate (FRR) equals the false acceptance rate (FAR) is known as the:

Hard
29

A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?

Medium
30

Which access control model enforces security based on classification labels assigned to subjects and objects, commonly used for confidentiality?

Easy
31

In Role-Based Access Control (RBAC), what is the purpose of role hierarchy?

Medium
32

An organization implements a policy requiring passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 60 days. Which password policy elements are being enforced?

Medium
33

A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?

Medium
34

A security administrator is configuring a new system and wants to enforce a mandatory access control model to ensure confidentiality of classified data. Which access control model should the administrator implement?

Medium
35

An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?

Medium
36

What is the primary risk associated with service accounts in an enterprise?

Medium
37

A security auditor is reviewing the account lifecycle process. Which TWO of the following are mandatory steps during the deprovisioning (offboarding) process?

Hard
38

Which authentication method generates a one-time password that is valid for only a short time window?

Easy
39

In a Bell-LaPadula model implementation, a user with a Secret clearance attempts to read a document classified as Top Secret. Additionally, they try to write to a document classified as Unclassified. What are the results of these actions?

Hard
40

A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?

Easy
41

Which access control model allows the owner of a resource to grant access permissions to other users?

Easy
42

What is the primary purpose of a Privileged Access Management (PAM) solution?

Easy
43

What is the primary purpose of account deprovisioning?

Easy
44

What is the primary purpose of account deprovisioning in the account lifecycle?

Easy
45

An organization requires users to authenticate using a password and a one-time code from a mobile app. Which authentication method is being used?

Easy
46

A security administrator is designing an identity federation solution. Which THREE of the following are commonly used federation standards?

Medium
47

A company is implementing single sign-on (SSO) for its internal applications. Which TWO of the following protocols are commonly used for SSO?

Medium
48

An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?

Medium
49

A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?

Medium
50

During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?

Hard
51

A security engineer is designing a system that must ensure data integrity at all costs, even if it means sacrificing availability. Which access control model and corresponding principle should be applied?

Hard
52

Which TWO of the following are characteristics of the Biba integrity model? (Choose TWO.)

Medium
53

A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?

Easy
54

An Identity Provider (IdP) sends an XML-based assertion to a Service Provider (SP) to grant access. Which federated identity standard is being used?

Medium
55

A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)

Hard
56

In a federated identity scenario, a user authenticates to their home domain and accesses a resource in a partner domain. The partner domain trusts the authentication performed by the home domain. What is the home domain's role in this trust relationship?

Hard
57

An organization uses Kerberos for single sign-on (SSO) within its Windows domain. Which component issues ticket-granting tickets (TGTs) after verifying user credentials?

Medium
58

An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?

Medium
59

An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?

Hard
60

An organization is planning to implement a Single Sign-On (SSO) solution. Which THREE of the following are commonly associated with SSO technologies?

Medium
61

An organization is planning to implement multi-factor authentication. Which TWO of the following are valid authentication factors?

Easy
62

An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?

Medium
63

A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?

Medium
64

An organization is implementing a password policy that requires passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 90 days. Additionally, users cannot reuse any of the last 10 passwords. Which password policy element does the last requirement address?

Hard
65

A user claims to be 'jsmith' and provides a password. What is the term for the step where the system verifies that the password matches the one on file for 'jsmith'?

Medium
66

Which of the following is the correct order of the access control process?

Easy
67

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

Medium
68

In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?

Hard
69

An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)

Hard
70

An IT administrator needs to deprovision a user who has been terminated. Which of the following actions should be performed first to ensure security?

Medium
71

An organization uses Kerberos for single sign-on. When a user logs in, they receive a Ticket Granting Ticket (TGT). What is the primary purpose of the TGT?

Medium
72

Which of the following best describes the concept of accountability in access controls?

Medium
73

Which authentication method uses a time-based one-time password (TOTP) generated by a hardware or software token?

Easy
74

A security architect is designing an access control system for a healthcare application. The system must ensure that a nurse can view patient records but cannot modify them, and that a doctor can both view and update records. Additionally, the system must prevent a single user from both ordering a medication and approving its administration. Which TWO access control principles are being applied? (Select TWO.)

Medium
75

An organization is implementing a privileged access management (PAM) solution. Which THREE of the following are common PAM capabilities?

Medium
76

Which access control model allows the owner of a resource to determine who can access it and what privileges they have?

Easy
77

A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?

Easy
78

An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?

Hard
79

A security architect is designing an access control system for a healthcare application that requires fine-grained access decisions based on user role, location, time of day, and patient consent. Which TWO access control models are best suited for this requirement?

Hard
80

Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?

Medium

Frequently asked questions

What does the Access Controls domain cover on the SSCP exam?
Access Controls questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 80 Access Controls questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Access Controls questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp access controls Practice Questions