Courseiva

SSCP · domain

Access Controls

Access Controls covers how subjects are identified, authenticated, authorized, and deprovisioned across the account lifecycle. SSCP questions test model selection (MAC, DAC, RBAC, ABAC), authentication factors and one-time passwords, least privilege, separation of duties, and the correct order of termination actions such as disabling accounts before removing access.

100 questions24 easy47 medium29 hard

Focused practice

Practice Access Controls questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Access Controls

Be able to map a scenario to the right access control model, authentication factor, or lifecycle step, and state the action order. The single most important thing: on termination, disable the account first, then remove or transfer access and data before deletion.

Distinguishing MAC, DAC, RBAC, and ABAC based on how permissions are assigned

Selecting authentication factors: something you know, have, or are

Ordering account lifecycle steps: provisioning, review, and deprovisioning on termination

Applying least privilege, need to know, and separation of duties controls

Watch out for

Common Access Controls exam traps

  • ▸Confusing MAC with DAC: MAC uses labels and clearances, while DAC lets the object owner set permissions.
  • ▸Deleting a terminated user's account before disabling it, losing audit trail and risking residual access.
  • ▸Treating RBAC as clearance-based; RBAC assigns permissions through roles, not subject clearance versus object classification.

Question index

All Access Controls questions (100)

Click any question to see the full explanation, or start a practice session above.

1

An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?

Hard
2

A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?

Medium
3

A company implements a password policy requiring a minimum length of 12 characters, including uppercase, lowercase, digits, and special characters. Passwords must be changed every 90 days, and the last 10 passwords cannot be reused. After a brute-force attack, several accounts were compromised despite the policy. Which additional control would most effectively mitigate such attacks?

Hard
4

A security team is designing an access control system for a research facility. They need a model that supports fine-grained, dynamic access decisions based on user department, project assignment, time of day, and the sensitivity of the resource. The model must also allow policies to be expressed in a human-readable language and evaluated at runtime. Which access control model best fits these requirements?

Hard
5

An organization uses ABAC to control access to a document. Which attribute combination would be used to allow access only during business hours from a managed device?

Hard
6

A security administrator is configuring a Linux server that hosts a shared project directory. The requirement is that new files created in the directory /projects/team must automatically inherit the group owner of the parent directory rather than the primary group of the user who created them. The administrator wants the setting to apply only to that directory. Which command should the administrator use?

Medium
7

An organization is implementing multi-factor authentication (MFA). Which TWO of the following are examples of something you have?

Medium
8

During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?

Hard
9

A security team is reviewing access control models for a new document management system. The system must support discretionary sharing where document owners can grant access to other users, but it must also enforce a mandatory rule that any document labeled 'Confidential' cannot be accessed by users without a 'Confidential' clearance, regardless of owner intent. Which access control model best satisfies both requirements?

Hard
10

Which access control model allows the owner of a resource to grant permissions to others?

Easy
11

An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?

Hard
12

A hospital uses a MAC-based system where data labels carry classifications such as Restricted and Public, and user clearances are assigned by the security office. A nurse with a Secret-equivalent clearance attempts to read a patient record labeled with a higher classification. According to the Bell-LaPadula model, what should occur?

Hard
13

An organization is reviewing its account lifecycle management process. Which TWO activities are part of the provisioning phase? (Select TWO.)

Medium
14

In a Kerberos environment, what is the primary function of the Ticket Granting Ticket (TGT)?

Medium
15

A security administrator is configuring a network access control deployment that must authenticate employee laptops before they receive an IP address on the corporate VLAN. The administrator wants to use the IEEE 802.1X framework. Which two components are required for this framework to function? (Choose two.)

Medium
16

An organization uses OAuth 2.0 for delegated access to a cloud storage API. A third-party application requests an access token to read user files. What is the primary purpose of the access token in OAuth?

Medium
17

A security analyst is reviewing access controls for a database server. The database administrator has granted all users in the 'sales' role SELECT, INSERT, UPDATE, and DELETE permissions on the 'orders' table. Which access control principle is being violated?

Medium
18

A security consultant is reviewing an organization's identity and access management (IAM) architecture. The organization wants to implement a system where users can authenticate once and access multiple independent systems without re-entering credentials, while also enabling centralized session termination. Which TWO of the following are appropriate components or protocols to meet these requirements? (Choose two.)

Hard
19

A small business wants to implement single sign-on so employees can authenticate once and reach several internal web applications without re-entering credentials. The applications support SAML 2.0. Which component issues the signed assertion that the applications consume to establish the user's identity?

Easy
20

A company is implementing a new access control system and wants to ensure that users are granted only the minimum permissions necessary to perform their job functions. Which principle is being applied?

Medium
21

A biometric system has a high false rejection rate (FRR). Which of the following is a likely consequence?

Medium
22

Which term describes the process of verifying the identity of a user, system, or entity?

Easy
23

A hospital wants clinicians to reach patient records from any ward workstation without signing in repeatedly, but it also wants a single authoritative source of identity so that disabling an employee in the human resources system immediately removes clinical access. The identity team proposes using the Lightweight Directory Access Protocol (LDAP) as that authoritative store. Which statement best describes what LDAP provides in this design?

Hard
24

Which access control model enforces the principle of least privilege by granting permissions based on job functions and requires separation of duties?

Easy
25

A security administrator needs to implement an access control model that grants access based on attributes of the user, resource, and environment, using policy rules. Which model is most appropriate?

Medium
26

Which of the following is a common method for implementing multi-factor authentication (MFA) using something you have and something you know?

Easy
27

In the Bell-LaPadula model, which property prevents a subject from reading an object at a higher classification level?

Medium
28

A retail chain issues each cashier a badge containing a photograph and a scannable code. At the start of every shift, a supervisor visually compares the badge photograph to the person and scans the code into the point-of-sale terminal. Which two access control components are being combined in this process?

Easy
29

An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?

Medium
30

A financial services firm is deploying a centralized access control server that will make authorization decisions for dozens of internal applications. The architects want the applications to query a single decision point instead of embedding their own permission logic. Which two characteristics should the chosen model exhibit? (Choose two.)

Medium
31

In an OAuth 2.0 authorization flow, a client application receives an access token. This token is used to:

Hard
32

In a biometric system, the point at which the false rejection rate (FRR) equals the false acceptance rate (FAR) is known as the:

Hard
33

A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?

Medium
34

Which access control model enforces security based on classification labels assigned to subjects and objects, commonly used for confidentiality?

Easy
35

An organization implements a policy requiring passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 60 days. Which password policy elements are being enforced?

Medium
36

A healthcare organization deploys a new electronic records system. Clinicians may access patient records only while assigned to the cardiology department, and access is automatically revoked when they rotate to oncology. Which access control model best supports this requirement?

Hard
37

A retail company issues contactless smart cards to employees for physical entry to its data center. The security manager wants to ensure that a lost card cannot be used by someone who finds it, without adding a fingerprint reader at every door. Which access control enhancement best meets this requirement?

Easy
38

A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?

Medium
39

A security administrator is configuring a new system and wants to enforce a mandatory access control model to ensure confidentiality of classified data. Which access control model should the administrator implement?

Medium
40

A hospital is deploying a new electronic health records (EHR) system. The security team wants to ensure that access decisions are based on the user's assigned job function rather than on the user's identity or resource ownership. Which access control model best meets this requirement?

Medium
41

An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?

Medium
42

What is the primary risk associated with service accounts in an enterprise?

Medium
43

A financial firm is designing access controls for a trading application. The firm wants to prevent any single employee from both initiating a large funds transfer and approving it, and it also wants to ensure that access rights are automatically revoked when an employee changes departments. Which combination of principles is the firm applying?

Hard
44

A financial institution uses a centralized authentication system. An auditor notes that when an employee is terminated, their access to several critical applications remains active for up to 24 hours because each application maintains its own local user database. Which of the following is the MOST effective control to reduce this window of exposure?

Hard
45

Which authentication method generates a one-time password that is valid for only a short time window?

Easy
46

A software company wants outside contractors to reach a single internal source code repository without creating accounts in the company directory. The identity team proposes using the Security Assertion Markup Language so that contractors authenticate against their own employer's identity provider. Which statement describes the trust relationship that must exist for this to work?

Medium
47

In a Bell-LaPadula model implementation, a user with a Secret clearance attempts to read a document classified as Top Secret. Additionally, they try to write to a document classified as Unclassified. What are the results of these actions?

Hard
48

A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?

Easy
49

Which access control model allows the owner of a resource to grant access permissions to other users?

Easy
50

A security administrator is implementing a biometric access control system for a data center. The organization wants to minimize the chance that an unauthorized person is granted access, even if it means legitimate users occasionally have to retry. Which metric should the administrator tune to achieve this goal?

Medium
51

A healthcare organization uses a mandatory access control (MAC) system to protect patient records. A nurse with a Secret clearance attempts to access a file classified as Top Secret. According to the Bell-LaPadula model, what will happen?

Medium
52

What is the primary purpose of a Privileged Access Management (PAM) solution?

Easy
53

A small business wants employees to authenticate to the corporate VPN using a hardware token that generates a time-based one-time code in addition to their password. Which authentication factor category does the hardware token represent?

Easy
54

What is the primary purpose of account deprovisioning?

Easy
55

What is the primary purpose of account deprovisioning in the account lifecycle?

Easy
56

An organization requires users to authenticate using a password and a one-time code from a mobile app. Which authentication method is being used?

Easy
57

A company is implementing single sign-on (SSO) for its internal applications. Which TWO of the following protocols are commonly used for SSO?

Medium
58

An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?

Medium
59

A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?

Medium
60

During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?

Hard
61

A security administrator is designing an access control scheme for a research lab where data sensitivity varies widely and the organization wants the operating system itself to enforce access decisions based on labels, independent of user discretion. Which TWO of the following characteristics apply to mandatory access control (MAC)? (Choose two.)

Hard
62

Which TWO of the following are characteristics of the Biba integrity model? (Choose TWO.)

Medium
63

A security administrator is configuring access controls for a shared file server. The administrator wants to grant permissions based on the sensitivity labels of the files and the clearance levels of the users, ensuring that users cannot change these permissions. Which access control model should be implemented?

Easy
64

A financial services firm wants to let customers authorize a third-party budgeting application to read their account transaction history without sharing their banking password. Which technology should the firm deploy?

Medium
65

A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?

Easy
66

A company is implementing a biometric authentication system for physical access to a data center. The system must minimize false acceptances. Which metric is most directly related to false acceptance rate (FAR)?

Medium
67

A small business owner wants to implement access control for a shared file server. The owner wants each department manager to be able to decide which of their employees can access specific folders, without involving the IT department for every change. Which access control model is most appropriate for this requirement?

Easy
68

A security administrator at a financial firm is configuring access control for a new document management system. The system must enforce access decisions based on the sensitivity labels of documents and the clearance levels of employees, and it must prevent users from delegating their access to others. Which access control model should the administrator implement?

Medium
69

A company deploys a RADIUS server for wireless 802.1X authentication. Users report that after a password change, their devices still authenticate successfully for several hours using cached credentials. Which RADIUS behavior most likely explains this?

Medium
70

An Identity Provider (IdP) sends an XML-based assertion to a Service Provider (SP) to grant access. Which federated identity standard is being used?

Medium
71

A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)

Hard
72

A security auditor is evaluating a company's implementation of mandatory access control (MAC) using a commercial trusted operating system. The auditor needs to verify that the MAC implementation correctly enforces the no read up and no write down rules for confidentiality. Which TWO of the following are essential characteristics the auditor should confirm? (Choose two.)

Hard
73

In a federated identity scenario, a user authenticates to their home domain and accesses a resource in a partner domain. The partner domain trusts the authentication performed by the home domain. What is the home domain's role in this trust relationship?

Hard
74

An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?

Medium
75

A defense contractor runs an air-gapped laboratory where removable media are used to move engineering data between isolated enclaves. Policy requires that a workstation be usable only when a specific approved removable device is inserted, and that the workstation become unusable the instant that device is removed. Which access control approach best enforces this behavior?

Hard
76

An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?

Hard
77

A financial institution uses a RADIUS server for centralized authentication of its VPN users. A security administrator notices that authentication requests from a new VPN concentrator are being rejected, while requests from other devices work fine. The RADIUS server logs show that the shared secret does not match. What is the most likely cause?

Hard
78

An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?

Medium
79

A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?

Medium
80

An organization is implementing a password policy that requires passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 90 days. Additionally, users cannot reuse any of the last 10 passwords. Which password policy element does the last requirement address?

Hard
81

A user claims to be 'jsmith' and provides a password. What is the term for the step where the system verifies that the password matches the one on file for 'jsmith'?

Medium
82

Which of the following is the correct order of the access control process?

Easy
83

A healthcare organization must enforce access control based on a combination of the user's assigned department, the classification of the data being accessed, and the time of day. Users in the cardiology department may view patient records only during their scheduled shift, and only if the record belongs to a patient currently admitted to cardiology. Which access control model BEST supports these requirements?

Medium
84

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

Medium
85

A security analyst is reviewing authentication logs and notices that a user account was used to log in from two different geographic locations within a five-minute window. The organization uses a centralized RADIUS server for authentication. Which of the following should the analyst investigate FIRST to determine if this is a legitimate concurrent session or a compromise?

Easy
86

A security team is hardening a centralized authentication service and wants to reduce the risk of credential replay and lateral movement if a password is compromised. Which TWO of the following controls directly support this goal? (Choose two.)

Medium
87

In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?

Hard
88

An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)

Hard
89

An IT administrator needs to deprovision a user who has been terminated. Which of the following actions should be performed first to ensure security?

Medium
90

An organization uses Kerberos for single sign-on. When a user logs in, they receive a Ticket Granting Ticket (TGT). What is the primary purpose of the TGT?

Medium
91

Which of the following best describes the concept of accountability in access controls?

Medium
92

A security architect is designing an access control system for a healthcare application. The system must ensure that a nurse can view patient records but cannot modify them, and that a doctor can both view and update records. Additionally, the system must prevent a single user from both ordering a medication and approving its administration. Which TWO access control principles are being applied? (Select TWO.)

Medium
93

An organization is implementing a privileged access management (PAM) solution. Which THREE of the following are common PAM capabilities?

Medium
94

A hospital uses a discretionary access control model on its file shares. A department head grants a colleague read access to a folder containing protected health information so they can cover a vacation. Months later an audit finds the access still active after the coverage ended. Which characteristic of discretionary access control most directly explains why this happened?

Hard
95

A company uses discretionary access control (DAC) for its file shares. A project manager creates a folder and wants to grant a team member read-only access. Which of the following best describes how access is determined in this model?

Medium
96

Which access control model allows the owner of a resource to determine who can access it and what privileges they have?

Easy
97

A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?

Easy
98

An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?

Hard
99

Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?

Medium
100

A small business owner wants to implement access control for a shared folder on a Windows server. The owner wants to grant different permissions to individual employees based on their specific job duties, without creating groups. Which access control model is most appropriate?

Easy

Frequently asked questions

What does the Access Controls domain cover on the SSCP exam?
Be able to map a scenario to the right access control model, authentication factor, or lifecycle step, and state the action order. The single most important thing: on termination, disable the account first, then remove or transfer access and data before deletion.
How many questions are in this domain?
This page lists all 100 Access Controls questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Access Controls questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp access controls Practice Questions