Courseiva

CCNA Access Controls Questions

75 of 100 questions · Page 1/2 · Access Controls · Answers revealed

1
MCQhard

An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?

A.Three-factor authentication
B.Single-factor authentication
C.Two-factor authentication
D.Biometric authentication
AnswerC

The smart card holds a PKI certificate (something you have) while the PIN is something you know. Combining these two distinct factors satisfies two-factor authentication, unlike a single-factor method such as certificate-only or password-only verification.

Why this answer

Two-factor authentication requires two different categories of authentication factors. The smart card (something you have) plus the PIN (something you know) combine two distinct factor types, so this is two-factor authentication. The certificate on the card provides cryptographic proof of possession, while the PIN unlocks the card and proves knowledge.

Exam trap

SSCP often tests factor counting — candidates miscount because they treat the certificate and the PIN as two separate 'things' or forget that possession plus knowledge equals exactly two factors, not three.

How to eliminate wrong answers

Option A is wrong because three-factor authentication would require a third, different factor such as a biometric (something you are) in addition to the card and PIN. Option B is wrong because single-factor authentication uses only one factor category; here both possession and knowledge are required. Option D is wrong because biometric authentication relies on a physical characteristic (fingerprint, iris, face), which is not used in this scenario.

2
MCQmedium

A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?

A.Kerberos
B.SAML
C.OAuth 2.0
D.OpenID Connect
AnswerB

SAML exchanges authentication and authorisation data as XML assertions between an identity provider and a service provider, exactly the flow described. Its assertion-based, XML-encoded token format is the defining characteristic distinguishing it from other SSO protocols.

Why this answer

SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It uses XML assertions to convey user identity and attributes, making it the correct protocol for this scenario.

Exam trap

The trap is confusing SAML with OAuth or OIDC, especially since all are used for SSO, but only SAML uses XML assertions.

How to eliminate wrong answers

Option A is wrong because Kerberos is a network authentication protocol that uses tickets, not XML assertions, and is typically used within a domain, not for web SSO. Option C is wrong because OAuth 2.0 is an authorization framework that uses tokens (often JSON) for delegated access, not XML assertions for authentication. Option D is wrong because OpenID Connect is an authentication layer on top of OAuth 2.0 that uses JSON Web Tokens (JWT), not XML assertions.

3
MCQhard

A company implements a password policy requiring a minimum length of 12 characters, including uppercase, lowercase, digits, and special characters. Passwords must be changed every 90 days, and the last 10 passwords cannot be reused. After a brute-force attack, several accounts were compromised despite the policy. Which additional control would most effectively mitigate such attacks?

A.Use a password blacklist
B.Increase minimum password length to 16 characters
C.Implement account lockout after 5 failed attempts
D.Require password change every 30 days
AnswerC

Account lockout after five failed attempts halts repeated authentication guesses, so a brute-force attack cannot continue indefinitely against an account. Length and complexity rules alone do not stop sustained automated guessing, making lockout the control that directly mitigates this attack.

Why this answer

Account lockout after a small number of failed attempts directly defeats brute-force attacks by halting the attack after a threshold, regardless of password complexity. Even a 12-character complex password can eventually be brute-forced given unlimited attempts; lockout removes that unlimited-attempt advantage. This is the most effective additional control because it targets the attack mechanism itself rather than the password's guessability.

Exam trap

SSCP often tests the misconception that stronger password complexity alone stops brute-force attacks — the real defense is limiting the number of attempts via lockout or rate limiting.

How to eliminate wrong answers

Option A is wrong because a password blacklist only blocks known-weak or breached passwords at creation/change time; it does nothing to stop an attacker from brute-forcing an existing valid password. Option B is wrong because increasing length to 16 characters raises the search space but still permits unlimited guessing, so a determined attacker with time and compute can eventually succeed — it slows but does not stop brute force. Option D is wrong because more frequent password changes (30 days) actually encourages weaker, predictable password patterns and does not prevent brute-force attempts against the current password; NIST SP 800-63B now discourages forced periodic rotation.

4
MCQhard

A security team is designing an access control system for a research facility. They need a model that supports fine-grained, dynamic access decisions based on user department, project assignment, time of day, and the sensitivity of the resource. The model must also allow policies to be expressed in a human-readable language and evaluated at runtime. Which access control model best fits these requirements?

A.Attribute-based access control (ABAC)
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Discretionary access control (DAC)
AnswerA

ABAC evaluates attributes of subjects, objects, and the environment to make access decisions. It can incorporate department, project, time of day, and resource sensitivity dynamically. Policies can be written in languages like XACML, which are human-readable. This model provides the fine-grained, runtime evaluation required, making it the best fit for the research facility's needs.

Why this answer

Attribute-based access control (ABAC) is designed to evaluate multiple attributes—user, resource, and environmental—at runtime, enabling dynamic and fine-grained decisions. It supports policy languages such as XACML, which are human-readable. RBAC, MAC, and DAC do not offer this combination of dynamic attribute evaluation and expressive policy language, so ABAC is the correct choice.

Exam trap

The trap here is confusing RBAC's role assignments with ABAC's dynamic attribute evaluation, overlooking that only ABAC can incorporate environmental conditions like time of day at runtime.

5
MCQhard

An organization uses ABAC to control access to a document. Which attribute combination would be used to allow access only during business hours from a managed device?

A.User department and document creation date
B.User identity, time of day, and device compliance status
C.User role and document classification
D.Document owner and file size
AnswerB

User identity, time of day, and device compliance status map directly onto ABAC's three attribute categories: subject, environmental, and resource/device. Time of day satisfies the business-hours constraint, while device compliance status enforces the managed-device requirement, so the policy evaluates all three conditions together before granting document access.

Why this answer

ABAC (Attribute-Based Access Control) evaluates policies against attributes of the subject, resource, action, and environment. To allow access only during business hours from a managed device, the policy must combine a time-of-day environmental attribute with a device compliance attribute, plus the user identity to identify the subject. Option B lists exactly these three: user identity, time of day, and device compliance status.

Exam trap

The trap is confusing ABAC with RBAC — candidates pick role-based options (role + classification) because they look security-relevant, but ABAC specifically requires environmental and device attributes to enforce context-aware conditions like time and device posture.

How to eliminate wrong answers

Option A is wrong because department and document creation date do not address time-of-day or device posture — creation date is a resource attribute that has no bearing on when or from where access occurs. Option C is wrong because role and classification are RBAC/classification attributes; they cannot enforce time windows or device compliance, which are environmental and device attributes respectively. Option D is wrong because document owner and file size are irrelevant to temporal or device-based conditions; file size is not a security-relevant attribute for access decisions.

6
MCQmedium

A security administrator is configuring a Linux server that hosts a shared project directory. The requirement is that new files created in the directory /projects/team must automatically inherit the group owner of the parent directory rather than the primary group of the user who created them. The administrator wants the setting to apply only to that directory. Which command should the administrator use?

A.chmod +t /projects/team
B.setfacl -d -m g:team:rwx /projects/team
C.chown :team /projects/team
D.chmod g+s /projects/team
AnswerD

Setting the setgid bit on a directory causes new files and subdirectories created within it to inherit the directory's group ownership instead of the creator's primary group. This directly satisfies the requirement that files in /projects/team retain the team group. The command applies only to the specified directory and does not affect other paths, which matches the scoped requirement.

Why this answer

The setgid bit on a directory is the standard Unix mechanism for ensuring that files and subdirectories created within it inherit the directory's group ownership. This is commonly used for shared project directories where collaboration among group members is required. Other options either alter permissions without affecting ownership, change only the directory's group, or set the sticky bit, which controls deletion rather than ownership inheritance.

Exam trap

The trap here is confusing the sticky bit with the setgid bit, since both are special permission bits applied to directories but serve entirely different purposes.

7
Multi-Selectmedium

An organization is implementing multi-factor authentication (MFA). Which TWO of the following are examples of something you have?

Select 2 answers
A.Smart card
B.PIN
C.Retina scan
D.Hardware token (e.g., YubiKey)
E.Fingerprint
AnswersA, D

A smart card is a physical artefact issued to and held by the user, making it a possession factor. The embedded chip stores credentials or keys that the reader validates, so authentication depends on having the card rather than remembering a secret or presenting a biometric.

Why this answer

Something you have includes physical tokens like smart cards and hardware tokens. Biometrics are something you are, and passwords are something you know.

8
Multi-Selecthard

During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?

Select 2 answers
A.Role hierarchy
B.Least privilege
C.Separation of duties
D.Mandatory access control
E.Accountability
AnswersB, C

Holding two mutually exclusive roles grants access beyond what either role alone requires for the user's duties. Least privilege is violated because the accumulated permissions exceed the minimum necessary to perform the assigned job function.

Why this answer

Option B (Least privilege) is correct because assigning a user to two mutually exclusive roles grants them more permissions than their job function requires, violating the principle that users should receive only the minimum access necessary to perform their duties. Option C (Separation of duties) is correct because mutually exclusive roles are specifically designed to prevent one person from holding conflicting responsibilities (e.g., initiating and approving a transaction), and assigning both to a single user directly defeats that control. Option A (Role hierarchy) is not necessarily violated, since a hierarchy merely organizes roles by inheritance and does not inherently prohibit holding two roles.

Option D (Mandatory access control) is unrelated, as MAC relies on system-enforced labels and clearances rather than conflicting role assignments. Option E (Accountability) concerns traceability of actions to an individual, which is not directly breached by holding two mutually exclusive roles.

Exam trap

SSCP often tests the overlap between least privilege and separation of duties — candidates pick only one, but the question asks for TWO principles, and both are directly violated by mutually exclusive role assignment.

9
MCQhard

A security team is reviewing access control models for a new document management system. The system must support discretionary sharing where document owners can grant access to other users, but it must also enforce a mandatory rule that any document labeled 'Confidential' cannot be accessed by users without a 'Confidential' clearance, regardless of owner intent. Which access control model best satisfies both requirements?

A.Mandatory Access Control (MAC)
B.Discretionary Access Control (DAC)
C.Role-Based Access Control (RBAC)
D.A hybrid approach combining DAC and MAC
AnswerD

A hybrid model allows owners to grant discretionary access while also enforcing mandatory label-based restrictions. This satisfies both the need for owner-controlled sharing and the requirement that Confidential documents remain inaccessible to users without proper clearance. No single traditional model provides both capabilities, so combining them is necessary.

Why this answer

The scenario requires both discretionary sharing by owners and mandatory enforcement of confidentiality labels. DAC provides the former but not the latter, while MAC provides the latter but not the former. A hybrid approach that layers MAC enforcement over DAC permissions meets both requirements simultaneously, which is why it is the correct choice.

Exam trap

The trap here is assuming that DAC alone can enforce mandatory restrictions, when in fact DAC permissions can be overridden by users with ownership rights.

10
MCQeasy

Which access control model allows the owner of a resource to grant permissions to others?

A.Discretionary Access Control (DAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Role-Based Access Control (RBAC)
AnswerA

Discretionary Access Control satisfies the stem's requirement because the resource owner holds discretion over permissions, typically via access control lists, and can pass that authority to other subjects. Unlike mandatory or role-based models, DAC permits owner-initiated delegation, directly matching the scenario where an owner grants permissions to others.

Why this answer

Discretionary Access Control (DAC) is defined by the owner of an object having the discretion to grant or revoke access to other subjects, typically via ACLs on files or resources. This owner-controlled permission model is the defining characteristic of DAC, as opposed to MAC where the system enforces labels and RBAC where roles determine access.

Exam trap

The trap is confusing 'owner grants permissions' with RBAC or ABAC; candidates often pick RBAC because it sounds like delegated administration, but only DAC explicitly places grant authority with the resource owner.

How to eliminate wrong answers

Option B is wrong because ABAC grants access based on a combination of attributes (user, resource, environment, action) evaluated by policy, not on owner discretion. Option C is wrong because MAC uses system-assigned sensitivity labels and clearances; owners cannot arbitrarily grant access. Option D is wrong because RBAC assigns permissions to roles, and users inherit permissions through role membership — the owner does not individually grant access.

11
MCQhard

An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?

A.The owner of a document can grant read access to any other user.
B.Users in the 'HR' role can read documents classified as 'Confidential'.
C.All users with security clearance 'Secret' can read documents labeled 'Secret'.
D.If user.department == 'HR' AND doc.classification == 'Confidential' AND time.business_hours == true then permit read.
AnswerD

ABAC evaluates boolean rules combining multiple attributes of subject, resource, and environment. This rule matches user department, document classification, and time of day, then permits read, exactly the attribute-based evaluation model rather than role- or label-only checks.

Why this answer

Option D is correct because ABAC (Attribute-Based Access Control) evaluates policies built from multiple attributes — user, resource, action, and environment — combined with Boolean logic. The rule 'user.department == HR AND doc.classification == Confidential AND time.business_hours == true then permit read' explicitly combines a subject attribute (department), a resource attribute (classification), and an environmental attribute (time of day), which is the defining characteristic of an ABAC policy. NIST SP 800-162 defines ABAC as evaluating attributes of the subject, object, operation, and environment to make access decisions.

Exam trap

The trap here is confusing RBAC with ABAC — option B looks attribute-like because it mentions 'HR' and 'Confidential', but it is a role-based rule with no Boolean combination of subject, resource, and environmental attributes.

How to eliminate wrong answers

Option A is wrong because it describes a Discretionary Access Control (DAC) rule based on ownership and delegation, not attribute evaluation. Option B is wrong because it is a Role-Based Access Control (RBAC) rule — access is granted based on the user's role ('HR'), not on evaluated attributes. Option C is wrong because it is a Mandatory Access Control (MAC)/clearance-based rule (Bell-LaPadula style), where access is determined by comparing clearance levels rather than by evaluating a policy expression of multiple attributes.

12
MCQhard

A hospital uses a MAC-based system where data labels carry classifications such as Restricted and Public, and user clearances are assigned by the security office. A nurse with a Secret-equivalent clearance attempts to read a patient record labeled with a higher classification. According to the Bell-LaPadula model, what should occur?

A.The read is permitted because the nurse is accessing the record over an encrypted channel
B.The read is denied because no-read-up prevents reading higher-classified data
C.The read is allowed but only if the nurse first writes a justification to the audit log
D.The read is allowed because the nurse has a legitimate business need
AnswerB

Bell-LaPadula's simple security property, often called no-read-up, states that a subject cannot read an object with a classification higher than the subject's clearance. The nurse's clearance is lower than the record's label, so the read must be denied. This preserves confidentiality by preventing lower-cleared subjects from accessing more sensitive data, even when they have a legitimate operational reason to see it.

Why this answer

Bell-LaPadula enforces confidentiality through the simple security property, which forbids a subject from reading an object at a higher classification than the subject's clearance. Since the nurse's clearance is below the record's label, the read is denied. Business need, logging, and encryption do not alter the mandatory clearance comparison that drives the access decision.

Exam trap

The trap here is treating a legitimate business need as sufficient authorization, when mandatory access control models decide access purely from clearance and label relationships.

13
Multi-Selectmedium

An organization is reviewing its account lifecycle management process. Which TWO activities are part of the provisioning phase? (Select TWO.)

Select 2 answers
A.Creating user accounts in the identity store
B.Modifying user roles due to job change
C.Archiving user data for compliance
D.Assigning initial role memberships and permissions
E.Disabling accounts upon termination
AnswersA, D

Provisioning covers creating and placing identities into the store, so account creation is a core provisioning activity. It precedes ongoing maintenance tasks such as permission updates, reviews and eventual deprovisioning, satisfying the lifecycle phase the stem asks about.

Why this answer

Option A is correct because provisioning begins with creating the user account (identity) in the identity store, such as an LDAP directory or IdP, so the user has a unique identity to authenticate with. Option D is correct because provisioning also includes granting the initial entitlements — assigning the baseline role memberships and permissions the user needs on day one. Option B is not part of provisioning; modifying roles after a job change is a re-provisioning/change (mover) activity in the lifecycle.

Option C is not part of provisioning; archiving user data for compliance belongs to the deprovisioning/retention phase. Option E is not part of provisioning; disabling accounts on termination is a deprovisioning (leaver) activity.

Exam trap

SSCP often tests the boundary between provisioning and deprovisioning by offering role modification and account disabling as distractors, since candidates conflate all account changes with 'provisioning'.

14
MCQmedium

In a Kerberos environment, what is the primary function of the Ticket Granting Ticket (TGT)?

A.To store the user's password hash securely
B.To request service tickets from the Ticket Granting Service (TGS)
C.To provide a session key for encrypting communications
D.To authenticate the user to the Key Distribution Center (KDC)
AnswerB

After initial authentication, the client presents its TGT to the Ticket Granting Service. The TGS validates that ticket and issues service tickets for specific resources, so the TGT acts as the credential enabling service ticket requests without re-entering credentials.

Why this answer

The TGT is obtained after initial authentication and is used to request service tickets for various resources without re-authenticating.

15
Multi-Selectmedium

A security administrator is configuring a network access control deployment that must authenticate employee laptops before they receive an IP address on the corporate VLAN. The administrator wants to use the IEEE 802.1X framework. Which two components are required for this framework to function? (Choose two.)

Select 2 answers
A.A certificate revocation list published by the endpoint vendor
B.A domain name system server that resolves the switch management address
C.A mandatory captive portal that collects user consent before authentication
D.An authenticator that controls the port until authentication succeeds
E.An authentication server that validates the supplied credentials
AnswersD, E

The authenticator is the network device, such as a switch or wireless access point, that blocks or permits traffic on the controlled port based on the outcome of authentication. Without it, there is no enforcement point to hold the laptop in an unauthenticated state before an IP address is assigned. It relays credentials between the supplicant and the authentication server, making it an essential element of the framework.

Why this answer

The framework defines three roles, and the question asks for the two that the administrator must supply beyond the endpoint itself: the authenticator, which enforces port state on the switch or access point, and the authentication server, which validates credentials and returns authorization attributes. Together they hold the laptop in a pre-authentication state until the decision is rendered, which is what prevents an unauthenticated device from obtaining a corporate address.

Exam trap

The trap here is treating optional supporting infrastructure, such as revocation lists or captive portals, as core framework roles.

16
MCQmedium

An organization uses OAuth 2.0 for delegated access to a cloud storage API. A third-party application requests an access token to read user files. What is the primary purpose of the access token in OAuth?

A.To encrypt the user's data in transit
B.To store the user's credentials in the client application
C.To authorize the client to access the resource server on behalf of the user
D.To authenticate the user to the authorization server
AnswerC

The access token is a credential issued to the client after the user grants authorisation, and the resource server validates it to permit scoped access on the user's behalf. It carries granted permissions rather than the user's password or identity credentials.

Why this answer

The access token represents the authorized scope of access granted by the resource owner (user). It is used by the client to access the protected resource (e.g., API) without exposing user credentials.

17
MCQmedium

A security analyst is reviewing access controls for a database server. The database administrator has granted all users in the 'sales' role SELECT, INSERT, UPDATE, and DELETE permissions on the 'orders' table. Which access control principle is being violated?

A.Accountability
B.Separation of duties
C.Need to know
D.Least privilege
AnswerD

Granting every sales user full SELECT, INSERT, UPDATE and DELETE rights on orders exceeds what each user needs to perform their role. Least privilege requires only the minimum permissions necessary, so this blanket grant violates that principle as the stem describes.

Why this answer

Granting every user in the 'sales' role full SELECT, INSERT, UPDATE, and DELETE on the orders table violates least privilege, which requires granting only the minimum permissions needed for each user's job function. Most sales users likely need only SELECT (or limited INSERT), not DELETE or UPDATE. Broad role-wide grants exceed what any individual requires.

Exam trap

The trap is confusing least privilege with need to know — both are access principles, but least privilege is about the minimum permissions (CRUD scope) while need to know is about the minimum data (record/field scope).

How to eliminate wrong answers

Option A is wrong because accountability concerns traceability of actions to individuals (logging, unique IDs), not the scope of permissions granted. Option B is wrong because separation of duties requires splitting sensitive tasks among different people (e.g., one person creates a vendor, another approves payment) — it is not violated merely by over-granting permissions to a single role. Option C is wrong because need to know is closely related but typically applies to data classification and information access on a per-record basis; the more precise control principle violated by granting excessive CRUD permissions is least privilege.

18
Multi-Selecthard

A security consultant is reviewing an organization's identity and access management (IAM) architecture. The organization wants to implement a system where users can authenticate once and access multiple independent systems without re-entering credentials, while also enabling centralized session termination. Which TWO of the following are appropriate components or protocols to meet these requirements? (Choose two.)

Select 2 answers
A.Security Assertion Markup Language (SAML)
B.OAuth 2.0
C.Remote Authentication Dial-In User Service (RADIUS)
D.Lightweight Directory Access Protocol (LDAP)
E.OpenID Connect (OIDC)
AnswersA, E

SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider and service providers. It enables single sign-on across independent systems and supports centralized session management through the identity provider. When a user authenticates once, SAML assertions can be used to access multiple service providers, and terminating the session at the identity provider can invalidate access.

Why this answer

SAML and OpenID Connect are both federation protocols that enable single sign-on across independent systems. SAML uses XML assertions, while OIDC uses JSON Web Tokens and builds on OAuth 2.0. Both support centralized session management, allowing an identity provider to terminate sessions.

OAuth 2.0 is for authorization, and RADIUS and LDAP are not designed for web-based SSO or centralized session termination.

Exam trap

The trap here is assuming that OAuth 2.0 provides authentication, when it is actually an authorization framework; OpenID Connect is the authentication layer built on top of it.

19
MCQeasy

A small business wants to implement single sign-on so employees can authenticate once and reach several internal web applications without re-entering credentials. The applications support SAML 2.0. Which component issues the signed assertion that the applications consume to establish the user's identity?

A.The user agent (browser)
B.The service provider
C.The certificate authority
D.The identity provider
AnswerD

In SAML 2.0, the identity provider authenticates the user and issues a signed assertion containing authentication and attribute statements. The service provider trusts that signature and uses the assertion to establish a session. Since the business wants one authentication event to serve multiple applications, the identity provider is the component that generates the assertion the applications consume.

Why this answer

SAML 2.0 separates the identity provider, which authenticates users and issues signed assertions, from the service provider, which consumes and trusts them. The business needs one authentication event to reach multiple applications, so the identity provider is the issuing component. Certificate authorities and browsers support the exchange but do not create assertions.

Exam trap

The trap here is assuming the application or browser issues the identity assertion, when SAML places assertion issuance with the identity provider and consumption with the service provider.

20
MCQmedium

A company is implementing a new access control system and wants to ensure that users are granted only the minimum permissions necessary to perform their job functions. Which principle is being applied?

A.Need to know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerC

Least privilege is the principle that users should be granted only the minimum permissions necessary to perform their job functions. This directly matches the company's goal. By applying least privilege, the organization reduces the attack surface and limits potential damage from compromised accounts or insider threats.

Why this answer

The principle of least privilege states that users should be given only the minimum access rights required to perform their job functions. This exactly matches the company's goal of granting minimum necessary permissions. The other options represent different security concepts: separation of duties divides tasks, need to know focuses on information access, and defense in depth layers controls.

Exam trap

The trap here is confusing least privilege with need to know, since both involve restricting access, but need to know is specifically about information access, not general permissions.

21
MCQmedium

A biometric system has a high false rejection rate (FRR). Which of the following is a likely consequence?

A.The system will require less frequent calibration
B.Unauthorized users are more likely to gain access
C.Legitimate users may be denied access, leading to frustration
D.The system's crossover error rate (CER) will be very low
AnswerC

A high false rejection rate means the system wrongly refuses genuine users whose biometrics fail to match the stored template. The consequence is denied access for authorised individuals, causing frustration and extra helpdesk load. This directly satisfies the stem's FRR constraint, since FRR measures valid-user rejections, not impostor acceptance.

Why this answer

A high false rejection rate (FRR) means the biometric system incorrectly rejects legitimate users. This leads to frustration and potential productivity loss as authorized individuals are denied access. FRR is a key performance metric; a high FRR indicates the system is too strict.

Exam trap

SSCP often tests the confusion between FAR and FRR; candidates may incorrectly associate high FRR with unauthorized access (which is FAR) or with low CER, so remembering that FRR affects legitimate users is key.

How to eliminate wrong answers

Option A is wrong because a high FRR does not imply less frequent calibration; in fact, it may indicate the need for recalibration or threshold adjustment. Option B is wrong because unauthorized users gaining access is related to the false acceptance rate (FAR), not FRR. Option D is wrong because a low crossover error rate (CER) indicates a balanced system with low FRR and FAR; a high FRR would likely correspond to a higher CER, not lower.

22
MCQeasy

Which term describes the process of verifying the identity of a user, system, or entity?

A.Authorization
B.Authentication
C.Identification
D.Accountability
AnswerB

Authentication establishes and verifies a claimed identity by validating credentials such as passwords, certificates or biometrics, directly satisfying the stem's requirement to verify a user, system or entity. It is distinct from authorisation, which grants access rights after identity is confirmed, and from identification, which merely presents an identity claim.

Why this answer

Authentication is the process of verifying a claimed identity — typically by validating credentials such as passwords, biometrics, or tokens against stored data. It answers the question 'Are you who you say you are?' Identification is the prior step of claiming an identity, and authorization determines what that identity can do.

Exam trap

SSCP often tests the distinction between identification, authentication, authorization, and accountability — candidates frequently confuse authentication (verifying identity) with authorization (granting permissions) or identification (claiming identity).

How to eliminate wrong answers

Option A is wrong because authorization determines what resources or actions an authenticated identity is permitted to access — it happens after authentication and does not verify identity. Option C is wrong because identification is the act of claiming an identity (e.g., entering a username), which precedes and is distinct from verifying it. Option D is wrong because accountability is the ability to trace actions to a specific identity through logging and auditing, not the verification process itself.

23
MCQhard

A hospital wants clinicians to reach patient records from any ward workstation without signing in repeatedly, but it also wants a single authoritative source of identity so that disabling an employee in the human resources system immediately removes clinical access. The identity team proposes using the Lightweight Directory Access Protocol (LDAP) as that authoritative store. Which statement best describes what LDAP provides in this design?

A.LDAP is a hierarchical directory that can serve as the authoritative identity store and support authentication binds, but it does not by itself provide single sign-on or session management
B.LDAP provides the ticket-granting service that lets users obtain service tickets for clinical applications
C.LDAP issues signed assertions that workstations present to each other to establish single sign-on sessions
D.LDAP synchronizes credentials to each workstation so that local validation removes the need for a central authority
AnswerA

LDAP defines a directory information tree and operations such as bind, search, and modify, so it can hold accounts and validate credentials across the hospital. It is not a session or token service, so single sign-on across wards still requires an additional component such as Kerberos or a federation protocol layered on top of the directory.

Why this answer

The design needs an authoritative account repository plus a separate mechanism for cross-workstation session continuity. LDAP supplies the hierarchical directory and the bind operation that validates credentials, and disabling an account in that directory can take effect immediately. Single sign-on and session handling must come from an additional service, so the option that separates those responsibilities is the accurate description.

Exam trap

The trap here is conflating directory services with authentication frameworks, assuming that because LDAP stores passwords it must also deliver single sign-on tokens.

24
MCQeasy

Which access control model enforces the principle of least privilege by granting permissions based on job functions and requires separation of duties?

A.Attribute-Based Access Control (ABAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerB

RBAC assigns permissions to roles defined by job function rather than to individuals, so users receive only the access their duties require. Roles can also be structured to enforce separation of duties, satisfying both least privilege and the split-responsibility constraint in the stem.

Why this answer

Role-Based Access Control (RBAC) grants permissions based on job functions or roles, enforcing least privilege by giving users only the access their role requires. RBAC also supports separation of duties by ensuring no single role has excessive privileges, and by requiring multiple roles for sensitive operations. This matches the question's description precisely.

Exam trap

SSCP often tests the distinction between RBAC and ABAC/MAC/DAC, so candidates must recognize that 'job functions' and 'separation of duties' are signature RBAC characteristics, not attributes or labels.

How to eliminate wrong answers

Option A is wrong because ABAC grants access based on attributes (user, resource, environment) evaluated by policies, which is more dynamic than role-based and does not inherently enforce separation of duties through job functions. Option C is wrong because MAC uses security labels and clearances assigned by a central authority, enforcing confidentiality levels rather than job-function roles. Option D is wrong because DAC lets resource owners assign permissions at their discretion, which does not enforce least privilege or separation of duties systematically.

25
MCQmedium

A security administrator needs to implement an access control model that grants access based on attributes of the user, resource, and environment, using policy rules. Which model is most appropriate?

A.Attribute-Based Access Control (ABAC)
B.Mandatory Access Control (MAC)
C.Discretionary Access Control (DAC)
D.Role-Based Access Control (RBAC)
AnswerA

ABAC evaluates policy rules against attributes of subject, object and environment, so access decisions dynamically reflect context rather than static role or label assignments. This directly satisfies the requirement to grant access based on user, resource and environmental attributes.

Why this answer

ABAC is the correct answer because it evaluates access decisions dynamically using policy rules that combine attributes of the subject (user), the object (resource), and the environment (context such as time or location). This multi-attribute, policy-driven evaluation is the defining characteristic of ABAC, typically implemented via XACML or similar policy engines. MAC, DAC, and RBAC do not natively incorporate environmental or arbitrary resource attributes into their access decisions.

Exam trap

SSCP often tests the distinction between access control models by describing the decision input — candidates who see 'role' or 'label' keywords jump to RBAC or MAC, missing that the question specifies attributes of user, resource, and environment, which uniquely identifies ABAC.

How to eliminate wrong answers

Option B is wrong because MAC bases access decisions on security labels assigned to subjects and objects (e.g., Bell-LaPadula or Biba mandatory labels), not on flexible attribute-based policy rules. Option C is wrong because DAC lets resource owners set permissions at their discretion (e.g., via ACLs), which is identity/ownership-based rather than attribute-based. Option D is wrong because RBAC grants access based on the user's assigned role, not on a combination of user, resource, and environmental attributes.

26
MCQeasy

Which of the following is a common method for implementing multi-factor authentication (MFA) using something you have and something you know?

A.Fingerprint and retina scan
B.Smart card and PIN
C.Password and security question
D.Username and password
AnswerB

A smart card satisfies the "something you have" factor, while the PIN supplies "something you know". Combining a physical token with a memorised secret meets the stem's two-factor requirement, unlike single-factor or same-category pairings. This hardware-plus-knowledge pairing is a standard MFA implementation.

Why this answer

A smart card (something you have) combined with a PIN (something you know) satisfies the two-factor requirement using two distinct authentication factor categories. This is the classic possession-plus-knowledge MFA pairing and is widely deployed in PIV/CAC and physical access systems. The other options either use two factors from the same category or only one factor.

Exam trap

SSCP often tests whether candidates recognize that two methods from the same factor category (e.g., two biometrics or two passwords) do not constitute MFA — the trap is picking an option that sounds like two factors but is actually one category.

How to eliminate wrong answers

Option A is wrong because a fingerprint and a retina scan are both inherence factors (something you are), so combining them is single-category, not true MFA. Option C is wrong because a password and a security question are both knowledge factors (something you know), so this is not multi-factor. Option D is wrong because a username and password together constitute a single knowledge factor — a username is an identifier, not an authentication factor.

27
MCQmedium

In the Bell-LaPadula model, which property prevents a subject from reading an object at a higher classification level?

A.The *-property (no write down)
B.The Discretionary Security Property
C.The Simple Security Property (no read up)
D.The Lattice Security Property
AnswerC

The Simple Security Property forbids a subject at a lower classification from reading an object at a higher level, the no read up rule. This directly prevents upward information flow, which is the specific restriction the question describes.

Why this answer

The Simple Security Property (also called the no-read-up rule) in the Bell-LaPadula model states that a subject at a given security level cannot read an object at a higher classification level. This prevents unauthorized disclosure of classified information and is the foundational confidentiality rule of the model.

Exam trap

SSCP often tests the confusion between the Simple Security Property (no read up) and the *-property (no write down), since both are Bell-LaPadula rules but govern opposite operations.

How to eliminate wrong answers

Option A is wrong because the *-property (star property) governs write operations — it prevents a subject from writing down to a lower classification level, not reading up. Option B is wrong because the Discretionary Security Property uses an access matrix to control access based on need-to-know, not classification-level read restrictions. Option D is wrong because the Lattice Security Property is not a defined Bell-LaPadula property; Bell-LaPadula uses a lattice of security levels but the read restriction is specifically the Simple Security Property.

28
MCQeasy

A retail chain issues each cashier a badge containing a photograph and a scannable code. At the start of every shift, a supervisor visually compares the badge photograph to the person and scans the code into the point-of-sale terminal. Which two access control components are being combined in this process?

A.Authorization by the badge code and accounting by the supervisor's visual comparison
B.Identification by the badge code and authentication by the supervisor's visual comparison
C.Identification by the supervisor's visual comparison and authentication by the badge code
D.Authentication by the badge code and authorization by the supervisor's visual comparison
AnswerB

Presenting the badge code claims an identity, which is identification. The supervisor confirming that the person matches the photograph verifies that claim, which is authentication. Together they establish who the cashier is before the terminal grants any access, matching the two components the process combines.

Why this answer

The badge code is an assertion of who the cashier claims to be, and the supervisor's check that the face matches the photograph validates that assertion. Identification precedes authentication, and both precede the authorization decision the terminal makes about which functions the cashier may use.

Exam trap

The trap here is treating any credential presented at a checkpoint as authentication, when a bare identifier such as a badge number only claims an identity.

29
MCQmedium

An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?

A.Password and security question
B.Smart card and PIN
C.Password and one-time passcode (OTP)
D.Smart card and fingerprint
AnswerD

A smart card is a physical token, satisfying the "something you have" factor, while a fingerprint is a biometric trait, satisfying "something you are". Combining these two distinct factor types delivers true multi-factor authentication for remote access, unlike two passwords or two possession factors.

Why this answer

A smart card is a physical token the user possesses (something you have), and a fingerprint is a biometric trait inherent to the user (something you are). Combining them satisfies the requirement for two different MFA factor categories. This is a classic possession-plus-inherence pairing used in high-assurance environments.

Exam trap

SSCP often tests factor-category confusion — candidates see two credentials and assume MFA, missing that both must come from different categories (know, have, are).

How to eliminate wrong answers

Option A is wrong because both a password and a security question are knowledge factors (something you know), so they do not combine different factor categories. Option B is wrong because a smart card is possession but a PIN is knowledge, not inherence — it pairs 'have' with 'know', not 'have' with 'are'. Option C is wrong because a password is knowledge and an OTP is typically possession or knowledge depending on delivery, but neither is a biometric inherence factor.

30
Multi-Selectmedium

A financial services firm is deploying a centralized access control server that will make authorization decisions for dozens of internal applications. The architects want the applications to query a single decision point instead of embedding their own permission logic. Which two characteristics should the chosen model exhibit? (Choose two.)

Select 2 answers
A.Each application maintains its own copy of the permission tables so decisions can be made without network calls
B.Permissions are baked into each application's source code during development and released through the change management pipeline
C.Authorization decisions are expressed as policy that can be updated centrally and take effect without redeploying applications
D.A central policy engine evaluates subject, object, and environmental attributes at the moment of each request
E.The decision point grants access based solely on the user's job title stored in the human resources system
AnswersC, D

Centralized policy authoring means a change to rules propagates to all protected applications through the shared decision point rather than through code releases. This satisfies the architectural intent directly: the firm gains consistent enforcement and can adjust entitlements quickly, with the applications remaining unaware of the underlying rule changes.

Why this answer

Centralized authorization requires a shared decision point that evaluates rich context and a policy store that can be changed without touching application code. Attribute-based access control delivers both by evaluating subject, object, and environmental attributes in a central engine, and by expressing rules as centrally managed policy rather than as logic embedded in each application.

Exam trap

The trap here is equating centralization with speed, and therefore choosing local permission copies that quietly rebuild the fragmented logic the project set out to remove.

31
MCQhard

In an OAuth 2.0 authorization flow, a client application receives an access token. This token is used to:

A.Encrypt data between client and resource server
B.Identify the user across different applications
C.Authorize access to protected resources at the resource server
D.Authenticate the user to the authorization server
AnswerC

The access token is a credential presented to the resource server, which validates it and grants access to the protected resource. It authorises the request; it does not authenticate the user to the authorisation server or issue refresh tokens.

Why this answer

In OAuth 2.0, an access token is a credential that grants the client application delegated authorization to access specific protected resources on the resource server on behalf of the resource owner. It is presented to the resource server (typically as a Bearer token in the Authorization header) to prove the client has been authorized. The token does not authenticate the user to the authorization server, nor does it encrypt data — it authorizes API access.

Exam trap

SSCP often tests the confusion between authorization (OAuth access token) and authentication (OpenID Connect ID token), so candidates who conflate the two pick options about identifying or authenticating the user.

How to eliminate wrong answers

Option A is wrong because OAuth 2.0 access tokens do not encrypt data; encryption in transit is provided by TLS, and OAuth is an authorization framework, not a cryptographic transport mechanism. Option B is wrong because identifying a user across applications is the role of OpenID Connect's ID token (a JWT containing user identity claims), not the OAuth access token, which is opaque to the client and meant for the resource server. Option D is wrong because authenticating the user to the authorization server happens during the authorization grant flow (e.g., via the authorization endpoint and user login), not through the access token, which is issued after authentication and used for resource access.

32
MCQhard

In a biometric system, the point at which the false rejection rate (FRR) equals the false acceptance rate (FAR) is known as the:

A.False acceptance rate (FAR)
B.Crossover error rate (CER)
C.Failure to enroll rate
D.False rejection rate (FRR)
AnswerB

The crossover error rate is the threshold where false rejection rate and false acceptance rate intersect, giving a single comparable accuracy metric. A lower CER indicates a more accurate biometric system, useful when selecting between devices.

Why this answer

The crossover error rate (CER), also called the equal error rate (EER), is the point on the biometric operating curve where the false rejection rate equals the false acceptance rate. It is the standard metric for comparing the accuracy of different biometric systems — a lower CER indicates a more accurate system. The other options name individual rates or a different concept, not the crossover point.

Exam trap

SSCP often tests biometric metrics by describing the FRR=FAR intersection — candidates who confuse CER with FAR or FRR, or who don't recognize the 'crossover' terminology, pick the wrong rate instead of the crossover point.

How to eliminate wrong answers

Option A is wrong because FAR is only the false acceptance rate — the rate at which unauthorized users are incorrectly accepted — not the crossover point. Option C is wrong because the failure to enroll rate measures the proportion of users who cannot be enrolled in the system at all, which is unrelated to the FRR/FAR crossover. Option D is wrong because FRR is only the false rejection rate — the rate at which legitimate users are incorrectly rejected — not the crossover point.

33
MCQmedium

A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?

A.False Acceptance Rate (FAR)
B.Equal Error Rate (EER)
C.Crossover Error Rate (CER)
D.False Rejection Rate (FRR)
AnswerD

False Rejection Rate measures the proportion of legitimate users incorrectly denied access, which is exactly the high false-rejection symptom described. It is the biometric accuracy metric tied to Type I errors, unlike False Acceptance Rate, which covers impostors wrongly admitted.

Why this answer

The false rejection rate (FRR) is the metric that directly measures the proportion of legitimate users incorrectly rejected by a biometric system. A high number of false rejections is by definition a high FRR, so FRR is the metric most directly related to the reported issue. The other options describe different accuracy metrics or crossover points.

Exam trap

SSCP often tests biometric metrics by describing a symptom (too many false rejections) and asking for the metric — candidates who confuse FAR with FRR, or who pick CER/EER because it sounds more sophisticated, choose the wrong answer.

How to eliminate wrong answers

Option A is wrong because FAR measures false acceptances (unauthorized users let in), which is the opposite problem from false rejections. Option B is wrong because the Equal Error Rate is the point where FAR equals FRR, a comparative accuracy metric, not a direct measure of false rejections. Option C is wrong because the Crossover Error Rate is the same concept as EER — the intersection of FAR and FRR — and does not directly quantify the false rejection problem.

34
MCQeasy

Which access control model enforces security based on classification labels assigned to subjects and objects, commonly used for confidentiality?

A.Clark-Wilson
B.Brewer-Nash
C.Bell-LaPadula
D.Biba
AnswerC

Bell-LaPadula enforces confidentiality through mandatory access control, comparing classification labels on subjects and objects. Its no-read-up and no-write-down rules directly satisfy the stem's requirement for label-based enforcement, preventing lower-cleared subjects from accessing higher-classified data. This contrasts with integrity-focused models such as Biba, which reverse those rules.

Why this answer

Bell-LaPadula is a mandatory access control (MAC) model designed for confidentiality. It enforces the 'no read up, no write down' rules: a subject cannot read an object at a higher classification level, and cannot write to an object at a lower level. This prevents unauthorized disclosure of classified information and is widely used in government and military systems.

Exam trap

SSCP often tests the confusion between Bell-LaPadula (confidentiality, no read up/no write down) and Biba (integrity, no read down/no write up) — candidates who memorize only one direction of the rules pick the wrong model.

How to eliminate wrong answers

Option A is wrong because Clark-Wilson focuses on integrity through well-formed transactions and separation of duties, not confidentiality via classification labels. Option B is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest in commercial environments by dynamically restricting access based on what a subject has already accessed, not on static classification labels. Option D is wrong because Biba is the integrity counterpart to Bell-LaPadula, enforcing 'no read down, no write up' to prevent data corruption, not confidentiality.

35
MCQmedium

An organization implements a policy requiring passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 60 days. Which password policy elements are being enforced?

A.Complexity, expiry, and lockout
B.Length, complexity, and history
C.Length, complexity, and expiry
D.Length, complexity, and lockout
AnswerC

The policy enforces three distinct controls: a 12-character minimum (length), mixed character categories (complexity), and a 60-day rotation (expiry). Option C names all three elements the stem describes, matching each stated requirement precisely without adding unrelated controls such as history or lockout.

Why this answer

The policy specifies three elements: a minimum length of 12 characters (length), a requirement for uppercase, lowercase, digits, and special characters (complexity), and a 60-day change interval (expiry). Lockout and history are not mentioned in the policy, so they are not being enforced. The correct answer is length, complexity, and expiry.

Exam trap

SSCP often tests the ability to distinguish password policy elements — candidates see '12 characters' and 'uppercase/lowercase/digits/special' and '60 days' but may incorrectly add lockout or history because those are common in real policies, even though they are not stated in the question.

How to eliminate wrong answers

Option A is wrong because lockout (account lockout after failed attempts) is not mentioned in the policy — only complexity and expiry are present, and length is omitted from this option. Option B is wrong because history (preventing password reuse) is not mentioned; the policy does not state that previous passwords cannot be reused. Option D is wrong because lockout is not part of the policy, and history is also absent — only length, complexity, and expiry are enforced.

36
MCQhard

A healthcare organization deploys a new electronic records system. Clinicians may access patient records only while assigned to the cardiology department, and access is automatically revoked when they rotate to oncology. Which access control model best supports this requirement?

A.Role-based access control (RBAC)
B.Discretionary access control (DAC)
C.Attribute-based access control (ABAC)
D.Mandatory access control (MAC)
AnswerA

RBAC assigns permissions to roles rather than individuals, so a clinician's cardiology role grants record access only while assigned to it. Rotating to oncology means the cardiology role assignment is removed and the oncology role takes over, automatically changing access. This matches the requirement that access be tied to department membership and revoked upon rotation without per-user intervention.

Why this answer

The requirement ties access to a clinician's current department and revokes it upon rotation, which is precisely how role-based access control operates. Permissions are grouped into roles, and users receive access only through their assigned roles. When the cardiology role assignment is removed during rotation, access ends automatically, while the oncology role grants the appropriate new access.

This makes RBAC the most natural and administratively efficient fit.

Exam trap

The trap here is assuming that any model capable of expressing department membership, such as ABAC, is equally suitable, when the scenario is specifically about role assignments that change with job rotation.

37
MCQeasy

A retail company issues contactless smart cards to employees for physical entry to its data center. The security manager wants to ensure that a lost card cannot be used by someone who finds it, without adding a fingerprint reader at every door. Which access control enhancement best meets this requirement?

A.Require a personal identification number entered on the door keypad in addition to presenting the card
B.Increase the encryption key length used by the card's contactless interface
C.Enable anti-passback so the system rejects a card presented twice without an intervening exit
D.Shorten the card's validity period and require reissuance every quarter
AnswerA

Combining something the employee has, the smart card, with something the employee knows, a personal identification number, means a found card alone is insufficient for entry. This satisfies the requirement without adding biometric hardware at each door, and it is a straightforward two-factor implementation for physical access. The card still provides the credential, while the number proves the presenter is the authorized holder.

Why this answer

The requirement is to stop a finder from using a lost card, which calls for adding a second authentication factor tied to the person rather than the token. A personal identification number supplies that knowledge factor at low cost and without new biometric hardware at every door. Cryptography, expiration, and anti-passback all strengthen the credential system in different ways but none of them verifies who is presenting the card.

Exam trap

The trap here is equating stronger card security technology with verification of the person, when only an additional factor proves who is holding the card.

38
MCQmedium

A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?

A.Minimum 10 characters, no complexity, lockout after 3 attempts, history of 1
B.Minimum 6 characters, complexity required, lockout after 10 attempts, history of 5
C.Minimum 8 characters, no complexity, no lockout, password history of 3
D.Minimum 12 characters, complexity required, lockout after 5 attempts, history of 10
AnswerD

Twelve-character minimum length with complexity raises brute-force search space, lockout after five attempts throttles online guessing, and history of ten blocks reuse of previously compromised passwords. Together these settings address brute-force and credential-reuse vectors more strongly than any shorter or lockout-free combination.

Why this answer

The strongest brute-force protection combines a long minimum length (12 characters), complexity requirements, a tight lockout threshold (5 attempts), and a deep password history (10) to prevent reuse. Length exponentially increases the search space, complexity widens the character set, lockout throttles online guessing, and history blocks cycling back to old passwords.

Exam trap

SSCP often tests the trade-off between length, complexity, lockout, and history, tempting candidates to pick complexity-heavy but short passwords over longer ones.

How to eliminate wrong answers

Option A is wrong because 10 characters with no complexity and history of 1 is weaker — no complexity reduces the character set, and history of 1 allows immediate reuse of the previous password. Option B is wrong because 6 characters is far too short regardless of complexity or lockout, and lockout after 10 attempts is looser than 5. Option C is wrong because 8 characters with no complexity, no lockout, and history of 3 offers no brute-force throttling at all — an attacker can guess indefinitely.

39
MCQmedium

A security administrator is configuring a new system and wants to enforce a mandatory access control model to ensure confidentiality of classified data. Which access control model should the administrator implement?

A.Discretionary Access Control (DAC)
B.Biba
C.Role-Based Access Control (RBAC)
D.Bell-LaPadula
AnswerD

Bell-LaPadula enforces mandatory access control through no read up and no write down, preventing subjects from reading data above their clearance or leaking it to lower levels. This directly preserves confidentiality of classified data, unlike integrity-focused models such as Biba.

Why this answer

Bell-LaPadula is the mandatory access control model designed to enforce confidentiality using the 'no read up, no write down' rules (simple security property and *-property). It assigns security labels to subjects and objects and prevents lower-cleared subjects from reading higher-classified data, directly meeting the requirement to protect classified information.

Exam trap

SSCP often tests the confusion between Bell-LaPadula (confidentiality, no read up/no write down) and Biba (integrity, no read down/no write up) — candidates swap the two models.

How to eliminate wrong answers

Option A is wrong because DAC lets resource owners set permissions at their discretion, which cannot enforce mandatory confidentiality labels. Option B is wrong because Biba is the integrity model (no read down, no write up) — it protects data integrity, not confidentiality. Option C is wrong because RBAC assigns permissions based on roles, not classification labels, and is not a mandatory model in the Bell-LaPadula sense.

40
MCQmedium

A hospital is deploying a new electronic health records (EHR) system. The security team wants to ensure that access decisions are based on the user's assigned job function rather than on the user's identity or resource ownership. Which access control model best meets this requirement?

A.Discretionary Access Control (DAC)
B.Mandatory Access Control (MAC)
C.Role-Based Access Control (RBAC)
D.Rule-Based Access Control
AnswerC

RBAC assigns permissions to roles, and users are assigned to roles based on their job functions. In the hospital scenario, this means access to EHR functions is determined by the user's role (e.g., physician, nurse, billing clerk), not by individual identity or ownership. This aligns exactly with the requirement that access decisions be based on job function.

Why this answer

Role-Based Access Control (RBAC) is designed to assign permissions to roles, and users are then assigned to roles according to their job responsibilities. This directly satisfies the hospital's requirement that access be based on job function rather than individual identity or resource ownership. The other models either rely on ownership, labels, or global rules, which do not meet the stated need.

Exam trap

The trap here is confusing role-based access with rule-based access, assuming that any rule or policy that references job functions qualifies as RBAC.

41
MCQmedium

An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?

A.Password vaulting
B.Role-based access control
C.Multi-factor authentication
D.Just-in-Time (JIT) provisioning with session recording
AnswerD

Just-in-Time provisioning grants privileged rights only for the required window, then revokes them, satisfying the 'only when needed' constraint. Session recording captures all privileged activity for audit, meeting the recording requirement. Standing admin rights would fail both conditions.

Why this answer

Just-in-Time (JIT) provisioning grants privileged access only when needed and for a limited time, and session recording captures all activities for audit. Together, they directly satisfy the requirement that privileged accounts are used only when needed and all activities are recorded. JIT eliminates standing privileges, reducing the attack surface, while session recording provides non-repudiation and forensic evidence.

Exam trap

SSCP often tests the confusion between authentication controls (MFA), authorization models (RBAC), and PAM-specific controls (JIT + session recording) — candidates pick MFA or RBAC because they sound security-relevant but miss the 'only when needed' and 'recorded' requirements.

How to eliminate wrong answers

Option A is wrong because password vaulting stores and rotates privileged credentials but does not by itself enforce time-bound access or record sessions — it is a component of PAM, not the complete control described. Option B is wrong because role-based access control (RBAC) assigns permissions based on roles but does not provide just-in-time elevation or session recording; it is a static authorization model. Option C is wrong because multi-factor authentication strengthens authentication but does not limit when privileged accounts are used or record what is done with them.

42
MCQmedium

What is the primary risk associated with service accounts in an enterprise?

A.They are used by multiple users simultaneously
B.They are difficult to create
C.They often have excessive privileges and infrequent password changes
D.They are always tied to a specific user
AnswerC

Service accounts typically hold broad, long-lived credentials because they run automated processes, and their passwords are rarely rotated. This combination satisfies the stem's constraint: excessive privileges paired with infrequent password changes creates a prime target for lateral movement and credential abuse.

Why this answer

Service accounts are non-human accounts used by applications, daemons, or scheduled tasks to run processes and access resources. Because they must operate without interactive logon, they are frequently granted broad privileges (e.g., domain admin, local system) to ensure the service functions correctly. Additionally, their passwords are often set once and never rotated, or are hard-coded in scripts, making them a prime target for credential theft and lateral movement.

Thus, the primary risk is the combination of excessive privileges and infrequent password changes.

Exam trap

SSCP often tests the misconception that service accounts are secure because they are not used by humans, but the real risk is their excessive privileges and static credentials, which candidates may overlook in favor of less critical issues like shared use or difficulty of creation.

How to eliminate wrong answers

Option A is wrong because service accounts are typically designed for a single service or application, not for simultaneous use by multiple users; shared use is a characteristic of generic user accounts, not service accounts. Option B is wrong because creating a service account is generally straightforward—it involves provisioning a standard user account with specific rights—and difficulty is not a security risk. Option D is wrong because service accounts are explicitly not tied to a specific user; they are independent identities, and this independence is what allows them to run without human interaction, not a risk in itself.

43
MCQhard

A financial firm is designing access controls for a trading application. The firm wants to prevent any single employee from both initiating a large funds transfer and approving it, and it also wants to ensure that access rights are automatically revoked when an employee changes departments. Which combination of principles is the firm applying?

A.Zero trust and continuous authentication
B.Separation of duties and role-based access control with lifecycle management
C.Defense in depth and mandatory access control
D.Least privilege and need to know
AnswerB

Separation of duties ensures that no single individual controls both initiating and approving a sensitive transaction, directly matching the transfer requirement. Pairing this with role-based access control and lifecycle management means rights are tied to roles and updated automatically when an employee changes departments, which satisfies the revocation requirement. Together these principles address both stated objectives.

Why this answer

The requirement that one employee cannot both initiate and approve a transfer is the classic definition of separation of duties, which splits a sensitive process across multiple people. Automatically revoking or adjusting rights when an employee changes departments reflects role-based access control combined with lifecycle management, where access follows the current role rather than persisting indefinitely. Applying both principles together satisfies the firm's objectives.

Exam trap

The trap here is choosing least privilege alone, when least privilege governs how much access a user has rather than preventing one person from holding two conflicting duties.

44
MCQhard

A financial institution uses a centralized authentication system. An auditor notes that when an employee is terminated, their access to several critical applications remains active for up to 24 hours because each application maintains its own local user database. Which of the following is the MOST effective control to reduce this window of exposure?

A.Require employees to sign a security awareness policy acknowledging immediate termination of access.
B.Implement a mandatory password change every 30 days for all users.
C.Implement network access control (NAC) to restrict terminated employees' devices from connecting to the network.
D.Deploy a centralized identity management system with automated provisioning and deprovisioning.
AnswerD

A centralized identity management system can automate the provisioning and deprovisioning of accounts across all connected applications. When an employee is terminated, the system can immediately disable or delete their accounts in all integrated systems, eliminating the 24-hour delay caused by separate local databases. This directly addresses the root cause of the exposure.

Why this answer

The core issue is that each application maintains its own user database, causing manual and delayed deprovisioning. A centralized identity management system with automated provisioning and deprovisioning solves this by integrating with applications and immediately disabling accounts upon termination. The other options do not address the root cause of decentralized, delayed account revocation.

Exam trap

The trap here is focusing on perimeter or policy controls instead of the identity lifecycle management that actually revokes access across multiple systems.

45
MCQeasy

Which authentication method generates a one-time password that is valid for only a short time window?

A.Biometric scan
B.HMAC-based One-Time Password (HOTP)
C.Static password
D.Time-based One-Time Password (TOTP)
AnswerD

TOTP derives the one-time password from a shared secret combined with the current time step, so each code is valid only within a short window before the counter advances. That time-bound derivation is what limits validity, unlike event-based or static methods.

Why this answer

TOTP (Time-based One-Time Password, RFC 6238) generates a one-time password derived from a shared secret and the current time step (typically 30 seconds), so the code is valid only within a short time window. This time-bound validity is exactly what the question describes.

Exam trap

SSCP often tests the confusion between HOTP (counter-based) and TOTP (time-based), since both are OTP algorithms with similar names.

How to eliminate wrong answers

Option A is wrong because a biometric scan authenticates via a physical trait and does not generate a time-limited one-time password. Option B is wrong because HOTP (RFC 4226) is counter-based, not time-based — it increments a counter with each use, so codes don't expire on a time window. Option C is wrong because a static password does not change and has no time-limited validity.

46
MCQmedium

A software company wants outside contractors to reach a single internal source code repository without creating accounts in the company directory. The identity team proposes using the Security Assertion Markup Language so that contractors authenticate against their own employer's identity provider. Which statement describes the trust relationship that must exist for this to work?

A.Both organizations must share a single directory database that is replicated between their networks.
B.The company's service provider must trust assertions signed by the contractor's identity provider.
C.The contractor's identity provider must create shadow accounts for each user in the company directory.
D.The repository must issue a client certificate to each contractor before any assertion is accepted.
AnswerB

In a Security Assertion Markup Language exchange, the relying party accepts authentication statements only if it trusts the issuing authority. The company's repository acts as the service provider, and the contractor's employer acts as the identity provider, so a configured trust with the provider's signing certificate is mandatory. Without that trust relationship, the repository would treat incoming assertions as untrusted and deny access regardless of the contractor's credentials.

Why this answer

Federated authentication succeeds only when the relying party trusts the assertions issued by the partner identity provider, typically established by exchanging metadata and trusting the provider's signing certificate. Once that trust exists, contractors authenticate at their own employer and the repository consumes the signed assertion, so no local accounts are needed. This design keeps user lifecycle management with the employer while giving the company a verifiable basis for granting access.

Exam trap

The trap here is assuming federation requires local accounts or shared directories, when it actually depends on a configured trust in the partner's signed assertions.

47
MCQhard

In a Bell-LaPadula model implementation, a user with a Secret clearance attempts to read a document classified as Top Secret. Additionally, they try to write to a document classified as Unclassified. What are the results of these actions?

A.Read denied, write allowed
B.Read allowed, write allowed
C.Read denied, write denied
D.Read allowed, write denied
AnswerC

Reading is blocked by the no-read-up property, since Secret clearance cannot access Top Secret data. Writing is blocked by the no-write-down property, which prevents a Secret subject from leaking information to an Unclassified object. Both Bell-LaPadula constraints are therefore satisfied, denying each action.

Why this answer

Under Bell-LaPadula, the Simple Security Property (no read up) denies a Secret-cleared user from reading a Top Secret document. The *-Property (no write down) denies the same user from writing to an Unclassified document. Therefore, both the read and the write are denied.

Exam trap

SSCP often tests the direction of Bell-LaPadula rules — the trap is mixing up 'no read up' and 'no write down' with Biba's integrity rules, leading candidates to incorrectly allow the write down.

How to eliminate wrong answers

Option A is wrong because it incorrectly allows the write down to Unclassified, violating the *-Property. Option B is wrong because it allows both the read up (violating the Simple Security Property) and the write down (violating the *-Property). Option D is wrong because it allows the read up to Top Secret, which violates the Simple Security Property.

48
MCQeasy

A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?

A.Role-Based Access Control (RBAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Mandatory Access Control (MAC)
AnswerD

Mandatory Access Control enforces access decisions through system-assigned labels: each subject holds a clearance and each object a classification, and the operating system compares these to grant or deny access. Because users cannot alter labels or delegate permissions, this satisfies the stem's requirement that permissions derive from clearance and classification rather than owner discretion.

Why this answer

Mandatory Access Control (MAC) is the only model where access decisions are based on comparing the subject's security clearance with the object's classification label, as defined by a central authority. In MAC, the system enforces these labels and users cannot alter them, making it mandatory rather than discretionary. This matches the scenario of assigning permissions based on clearance and classification, which are core components of MAC (e.g., Bell-LaPadula or Biba models).

Exam trap

SSCP often tests the confusion between MAC and DAC, where candidates might think that any access control based on labels is discretionary, but the key differentiator is that MAC is system-enforced and non-discretionary, while DAC allows owner discretion.

How to eliminate wrong answers

Option A is wrong because RBAC assigns permissions based on roles within an organization, not on clearance and classification labels. Option B is wrong because DAC allows the owner of an object to determine access, which is discretionary and not based on system-wide clearance/classification. Option C is wrong because ABAC uses a combination of attributes (e.g., user, resource, environment) to make decisions, but it does not inherently rely on clearance and classification labels as the primary basis, and it is more granular and policy-driven.

49
MCQeasy

Which access control model allows the owner of a resource to grant access permissions to other users?

A.RBAC (Role-Based Access Control)
B.DAC (Discretionary Access Control)
C.MAC (Mandatory Access Control)
D.ABAC (Attribute-Based Access Control)
AnswerB

Discretionary Access Control lets the resource owner decide who receives permissions, satisfying the owner-grant constraint. Access rights are assigned at the owner's discretion via ACLs, unlike MAC or RBAC where policy or roles govern assignment.

Why this answer

DAC (Discretionary Access Control) is defined by the resource owner having discretion to grant or revoke access to other subjects, typically via ACLs or Unix file permissions. The owner decides who gets access, which is the defining characteristic of discretionary control. This is contrasted with MAC, where the system enforces access based on labels and clearances, not owner choice.

Exam trap

SSCP often tests the confusion between DAC (owner-controlled) and RBAC (role-controlled), so candidates pick RBAC when the question emphasizes 'owner grants access.'

How to eliminate wrong answers

Option A is wrong because RBAC grants access based on the user's role within the organization, not on the resource owner's discretion. Option C is wrong because MAC enforces access via system-assigned labels and clearances (e.g., Bell-LaPadula, Biba), removing owner discretion entirely. Option D is wrong because ABAC evaluates attributes (user, resource, environment) via policy, not owner-granted permissions.

50
MCQmedium

A security administrator is implementing a biometric access control system for a data center. The organization wants to minimize the chance that an unauthorized person is granted access, even if it means legitimate users occasionally have to retry. Which metric should the administrator tune to achieve this goal?

A.Crossover Error Rate (CER)
B.False Acceptance Rate (FAR)
C.False Rejection Rate (FRR)
D.Equal Error Rate (EER)
AnswerB

FAR measures the likelihood that an unauthorized user is incorrectly accepted. By tuning the system to lower the FAR, the administrator reduces the chance of granting access to impostors. This aligns with the goal of minimizing unauthorized access, even at the cost of more frequent retries by legitimate users, which would increase the False Rejection Rate.

Why this answer

The goal is to minimize unauthorized access, which means reducing the False Acceptance Rate. Lowering FAR makes the system stricter, accepting fewer impostors, though it may increase false rejections. CER and EER represent balanced points and do not prioritize security, while FRR relates to rejecting legitimate users, which is not the primary concern here.

Exam trap

The trap here is confusing FAR with FRR, or assuming that CER/EER is always the optimal setting, when the scenario explicitly prioritizes security over convenience.

51
MCQmedium

A healthcare organization uses a mandatory access control (MAC) system to protect patient records. A nurse with a Secret clearance attempts to access a file classified as Top Secret. According to the Bell-LaPadula model, what will happen?

A.The access will be allowed but the nurse will be required to sign an additional non-disclosure agreement.
B.The access will be denied because the nurse's clearance is lower than the file's classification.
C.The access will be denied because the nurse does not have Top Secret clearance, but the nurse can request a temporary upgrade.
D.The access will be allowed because the nurse has a legitimate need to know for patient care.
AnswerB

The Bell-LaPadula model enforces the no-read-up property: a subject cannot read an object with a higher sensitivity level. Since the nurse has Secret clearance and the file is Top Secret, the read is denied. This prevents unauthorized disclosure of classified information and is a core rule of MAC.

Why this answer

The Bell-LaPadula model is a mandatory access control model designed to protect confidentiality. Its no-read-up property states that a subject cannot read an object with a higher classification than the subject's clearance. Therefore, a nurse with Secret clearance cannot read a Top Secret file.

The other options either misunderstand the need-to-know principle, incorrectly assume that an NDA or temporary upgrade can bypass the rule, or misstate the model's behavior.

Exam trap

The trap here is confusing need to know with clearance level, assuming that a legitimate need to know can override the mandatory no-read-up rule.

52
MCQeasy

What is the primary purpose of a Privileged Access Management (PAM) solution?

A.Controlling and monitoring access to privileged accounts
B.Managing user password resets
C.Implementing single sign-on for all applications
D.Enforcing password complexity policies
AnswerA

PAM vaults privileged credentials, brokers sessions and records activity, so administrative access is granted only when required and fully auditable. This directly satisfies the requirement to control and monitor privileged accounts, rather than merely authenticating ordinary users.

Why this answer

A Privileged Access Management (PAM) solution is specifically designed to secure, control, and monitor the use of privileged accounts (e.g., root, administrator, service accounts) that have elevated permissions. It provides features like credential vaulting, session recording, just-in-time access, and approval workflows to prevent misuse and detect malicious activity. Unlike general identity management, PAM focuses on the high-risk accounts that can alter system configurations, access sensitive data, or disrupt operations.

Thus, controlling and monitoring access to privileged accounts is its primary purpose.

Exam trap

SSCP often tests the confusion between PAM and IAM, where candidates might select options related to general user management (like password resets or SSO) instead of recognizing that PAM specifically targets privileged accounts.

How to eliminate wrong answers

Option B is wrong because managing user password resets is a function of self-service password reset tools or identity and access management (IAM) systems, not PAM; PAM may include password rotation for privileged accounts but not general user resets. Option C is wrong because implementing single sign-on (SSO) for all applications is the role of an SSO or federated identity solution, which provides convenience and centralized authentication, whereas PAM focuses on securing privileged access, often with additional controls like session isolation. Option D is wrong because enforcing password complexity policies is typically handled by Group Policy, LDAP directory settings, or IAM platforms; PAM may enforce stronger policies for privileged credentials but its primary purpose is not general password policy enforcement.

53
MCQeasy

A small business wants employees to authenticate to the corporate VPN using a hardware token that generates a time-based one-time code in addition to their password. Which authentication factor category does the hardware token represent?

A.Something you are
B.Something you know
C.Something you have
D.Somewhere you are
AnswerC

A hardware token that generates time-based one-time codes is a possession factor, meaning the user must physically hold the device to authenticate. Combined with a password, which is a knowledge factor, this creates true multi-factor authentication because it draws on two different categories. The possession factor is exactly what the token contributes in this VPN scenario.

Why this answer

Authentication factors fall into categories including knowledge, possession, inherence, and location. A hardware token that generates time-based one-time codes must be physically held by the user, making it a possession factor. Pairing it with a password, which is a knowledge factor, satisfies multi-factor authentication because two different categories are required, rather than two instances of the same category.

Exam trap

The trap here is counting two credentials from the same category, such as a password plus a security question, as multi-factor authentication when only a single factor category is actually present.

54
MCQeasy

What is the primary purpose of account deprovisioning?

A.To revoke access and disable accounts when no longer needed
B.To create new user accounts
C.To audit user activity
D.To modify user roles
AnswerA

Deprovisioning removes or disables identities and revokes their entitlements once employment or the business need ends, closing the standing access that could otherwise be abused. It is the lifecycle counterpart to provisioning, not a password or permission review.

Why this answer

Account deprovisioning is the process of removing or disabling user accounts and revoking associated access rights when they are no longer required, such as when an employee leaves the organization or changes roles. The primary goal is to ensure that former users cannot access systems, data, or resources, thereby reducing the attack surface and preventing unauthorized access. This is a fundamental control in identity and access management (IAM) and is required by regulations like SOX, HIPAA, and PCI DSS.

Exam trap

SSCP often tests the distinction between provisioning and deprovisioning, and candidates may confuse deprovisioning with auditing or role changes, leading them to select an incorrect option that describes a related but different IAM function.

How to eliminate wrong answers

Option B is wrong because creating new user accounts is the purpose of account provisioning, not deprovisioning. Option C is wrong because auditing user activity is a monitoring function performed by logging and auditing systems, not the primary purpose of deprovisioning. Option D is wrong because modifying user roles is part of access management or role changes, which may trigger deprovisioning but is not its primary purpose.

55
MCQeasy

What is the primary purpose of account deprovisioning in the account lifecycle?

A.To modify user roles and permissions
B.To immediately disable accounts and preserve evidence
C.To enforce password policies
D.To create new user accounts
AnswerB

Deprovisioning immediately disables or removes access rights when a user leaves or changes roles, and retaining the account data preserves audit evidence for investigations. This containment-first approach satisfies the lifecycle requirement to revoke access promptly while keeping records intact for forensic or compliance review.

Why this answer

Deprovisioning is the formal process of removing a user's access when they leave or change roles. Its primary purpose is to immediately disable accounts to prevent unauthorized access while preserving the account and associated data as evidence for audits, investigations, or legal holds.

Exam trap

The trap is confusing deprovisioning with role modification or password policy enforcement — candidates forget that deprovisioning is specifically about terminating access while retaining records for audit and legal purposes.

How to eliminate wrong answers

Option A is wrong because modifying roles and permissions is part of access review or role change management, not deprovisioning — deprovisioning removes access entirely. Option C is wrong because enforcing password policies is a preventive access control applied during account provisioning and use, not during termination. Option D is wrong because creating new user accounts is provisioning — the opposite end of the lifecycle from deprovisioning.

56
MCQeasy

An organization requires users to authenticate using a password and a one-time code from a mobile app. Which authentication method is being used?

A.Time-based One-Time Password (TOTP)
B.Smart card
C.Hardware token
D.Biometrics
AnswerA

TOTP generates a code from a shared secret and the current time, so the mobile app produces a fresh one-time code every 30 seconds. Combined with the password, this delivers the two distinct factors the stem requires, satisfying the multi-factor authentication constraint.

Why this answer

A password combined with a one-time code generated by a mobile app is the textbook definition of Time-based One-Time Password (TOTP), where the code is derived from a shared secret and the current time (typically 30-second windows, per RFC 6238). This is a form of multi-factor authentication combining something you know (password) with something you have (the app/device).

Exam trap

The trap is conflating TOTP with hardware tokens — both generate one-time codes, but TOTP is software-based (mobile app) while hardware tokens are dedicated physical devices, and the exam expects you to key on the 'mobile app' detail.

How to eliminate wrong answers

Option B is wrong because a smart card is a physical card with an embedded chip used for authentication, not a software-generated time-based code on a mobile app. Option C is wrong because a hardware token is a dedicated physical device (like an RSA SecurID fob) that generates codes — the question specifies a mobile app, not dedicated hardware. Option D is wrong because biometrics uses physiological traits (fingerprint, face, iris) and does not involve a one-time code.

57
Multi-Selectmedium

A company is implementing single sign-on (SSO) for its internal applications. Which TWO of the following protocols are commonly used for SSO?

Select 2 answers
A.Kerberos
B.OAuth
C.LDAP
D.RADIUS
E.SAML
AnswersA, E

Kerberos provides ticket-based authentication within a trusted realm, issuing service tickets that let users access multiple internal applications without re-entering credentials. Its symmetric-key ticket exchange suits SSO for internal, domain-joined resources, satisfying the stem's requirement for a commonly used SSO protocol.

Why this answer

Kerberos (A) is a network authentication protocol that uses ticket-granting tickets (TGTs) and service tickets issued by a Key Distribution Center (KDC), enabling transparent single sign-on within a Windows/Active Directory domain environment. SAML (E) is an XML-based federation standard in which an identity provider (IdP) issues signed assertions to a service provider (SP), which is the classic browser-based SSO mechanism for internal and cloud applications. OAuth (B) is an authorization delegation framework (access tokens for APIs), not an authentication/SSO protocol by itself, so it does not fit the SSO requirement here.

LDAP (C) is a directory access protocol used to query and authenticate against a directory, but it does not provide cross-application SSO. RADIUS (D) is an AAA protocol for network access (VPN, Wi-Fi, 802.1X), not for application-level SSO.

Exam trap

The trap here is confusing authentication protocols with authorization or directory protocols; candidates often mistakenly select OAuth or LDAP because they are familiar with authentication concepts, but the question specifically asks for SSO protocols.

58
Multi-Selectmedium

An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?

Select 3 answers
A.Audit logging and monitoring of privileged actions
B.Role-based access control with mutually exclusive roles
C.Enforcing complex password policies
D.Using biometric authentication
E.Requiring two or more people to approve a transaction
AnswersA, B, E

Logging and monitoring privileged actions creates accountability and detects abuse, deterring fraud because no single actor can act unobserved. This detective control supports separation of duties by exposing attempts to combine conflicting responsibilities, satisfying the stem's requirement.

Why this answer

Option A (audit logging and monitoring of privileged actions) is correct because separation of duties requires accountability: recording and reviewing who did what (e.g., via SIEM, Windows Event Log, or syslog) deters and detects fraud by ensuring no single actor can act unobserved. Option B (role-based access control with mutually exclusive roles) is correct because RBAC assigns permissions to roles rather than individuals, and defining mutually exclusive roles (e.g., a user cannot hold both 'accounts payable' and 'accounts receivable' roles) technically prevents one person from controlling an entire transaction lifecycle. Option E (requiring two or more people to approve a transaction) is correct because dual control / two-person integrity (also called the four-eyes principle) splits a critical action across multiple parties, so no single individual can authorize a fraudulent transaction alone.

Option C (enforcing complex password policies) is not a separation-of-duties technique; it strengthens authentication against guessing/brute-force but does nothing to divide duties among people. Option D (using biometric authentication) is also not a separation-of-duties control; it improves identity assurance for a single user but does not prevent that user from holding conflicting responsibilities.

Exam trap

The trap is confusing authentication hardening (passwords, biometrics) with authorization controls like SoD; candidates may select password policies or biometrics thinking they enforce separation, but they only verify identity.

59
MCQmedium

A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?

A.MAC with Bell-LaPadula model
B.MAC with Biba model
C.DAC with owner-based permissions
D.RBAC with role hierarchy
AnswerA

Bell-LaPadula enforces mandatory access control through the no-read-up and no-write-down rules, matching the stated label comparisons exactly. Sensitivity labels on subjects and objects, rather than owner discretion, make the model mandatory, satisfying both the read and write constraints described.

Why this answer

The Bell-LaPadula model is a mandatory access control (MAC) model focused on confidentiality. Its two core rules are the Simple Security Property (no read up: a subject can only read objects at or below its clearance) and the Star Property (no write down: a subject can only write to objects at or above its clearance). The scenario describes exactly these two rules, so MAC with Bell-LaPadula is the correct answer.

Exam trap

SSCP often tests the confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up) — candidates who memorize only one direction of the rules pick the wrong model.

How to eliminate wrong answers

Option B is wrong because the Biba model enforces integrity, not confidentiality — its rules are 'no read down' and 'no write up,' the inverse of what the question describes. Option C is wrong because DAC relies on owner-assigned discretionary permissions rather than sensitivity labels and clearances. Option D is wrong because RBAC assigns permissions through roles based on job function, not through sensitivity labels and clearance levels.

60
MCQhard

During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?

A.Change the account to a service account and keep it active
B.Disable the account immediately and transfer ownership of files to the manager
C.Keep the account active but change the password and share it with the manager
D.Leave the account as-is and monitor activity for the week
AnswerB

Disabling the account immediately satisfies the revocation constraint while preserving the data for review. Unlike deletion, which destroys the identity and its associated content, disabling blocks all authentication through Microsoft Entra ID yet allows an administrator to transfer file ownership to the manager, granting the week-long access without reactivating the former employee's credentials.

Why this answer

Best practice for offboarding is to disable the account immediately upon termination to eliminate the risk of unauthorized access, while preserving the account for audit and file-ownership purposes. File ownership and access to needed data should be transferred to the manager or another designated employee, satisfying the business need without keeping credentials live. This balances security with operational continuity.

Exam trap

The trap here is the manager's request to 'keep the account active for a week' — candidates who prioritize business convenience over security pick C or D, forgetting that immediate disablement plus file-ownership transfer satisfies both needs.

How to eliminate wrong answers

Option A is wrong because converting a terminated user's account into a service account keeps active credentials tied to a departed employee, creating an unauthorized-access and accountability gap. Option C is wrong because sharing a password with the manager violates individual accountability and non-repudiation principles — actions would be logged under the former employee's identity. Option D is wrong because leaving the account active and merely monitoring it does not prevent misuse and violates the principle of least privilege and prompt revocation.

61
Multi-Selecthard

A security administrator is designing an access control scheme for a research lab where data sensitivity varies widely and the organization wants the operating system itself to enforce access decisions based on labels, independent of user discretion. Which TWO of the following characteristics apply to mandatory access control (MAC)? (Choose two.)

Select 2 answers
A.Access is granted based on the user's role within the organization rather than on labels
B.The operating system enforces access decisions through a reference monitor
C.Users may change the classification label of files they own to share them more easily
D.Resource owners can grant access at their discretion to any user they choose
E.Access decisions are based on security labels and clearances assigned by a central authority
AnswersB, E

MAC depends on a reference monitor that mediates every access request and compares subject clearance against object label. This enforcement is inside the trusted computing base and cannot be bypassed by users or applications. It directly satisfies the lab's requirement that the OS itself enforce decisions based on labels, making this a core MAC characteristic alongside centralized label assignment.

Why this answer

MAC is defined by centralized assignment of labels and clearances and by OS-level enforcement through a reference monitor. Users cannot alter labels or grant access at their discretion, and access is not determined by role membership. These two traits together satisfy the lab's need for label-based decisions that the operating system enforces independently of user choice.

Exam trap

The trap here is conflating discretionary owner control or role-based access with MAC, when MAC specifically removes user discretion and bases every decision on central labels and clearances.

62
Multi-Selectmedium

Which TWO of the following are characteristics of the Biba integrity model? (Choose TWO.)

Select 2 answers
A.No write-up
B.No write-down
C.No read-up
D.Discretionary access
E.No read-down
AnswersA, E

Subjects cannot write to higher integrity levels.

Why this answer

Option A, 'No write-up,' is correct because the Biba integrity model's *-integrity axiom (the write-up rule) forbids a subject from writing to an object of higher integrity level, preventing low-integrity data from contaminating higher-integrity data. Option E, 'No read-down,' is correct because Biba's simple integrity axiom forbids a subject from reading an object of lower integrity level, preventing a high-integrity subject from being corrupted by low-integrity data. Option B, 'No write-down,' actually belongs to the Bell-LaPadula confidentiality model (the *-property), which restricts writing to lower or equal sensitivity levels, not to Biba.

Option C, 'No read-up,' is also a Bell-LaPadula rule (the simple security property), prohibiting reading data at a higher classification, so it is not a Biba characteristic. Option D, 'Discretionary access,' describes discretionary access control (DAC) mechanisms such as owner-controlled ACLs, which are independent of the Biba mandatory integrity model and therefore not one of its defining characteristics.

Exam trap

SSCP often tests the mirror-image confusion between Biba (integrity: no write-up, no read-down) and Bell-LaPadula (confidentiality: no read-up, no write-down), so candidates who mix up the two models select the wrong pair.

63
MCQeasy

A security administrator is configuring access controls for a shared file server. The administrator wants to grant permissions based on the sensitivity labels of the files and the clearance levels of the users, ensuring that users cannot change these permissions. Which access control model should be implemented?

A.Role-Based Access Control (RBAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerC

MAC enforces access based on security labels assigned to objects (files) and clearances assigned to subjects (users). These labels and clearances are typically managed by a central authority, and users cannot alter them. This matches the requirement that access be based on sensitivity labels and clearance levels, and that users cannot change permissions.

Why this answer

Mandatory Access Control (MAC) is the only model that enforces access using sensitivity labels on objects and clearances on subjects, with permissions managed centrally so users cannot change them. This precisely matches the administrator's requirement. The other models either rely on roles, owner discretion, or flexible attributes, none of which provide the same mandatory, label-based enforcement.

Exam trap

The trap here is assuming that any label-based system is MAC, when in fact ABAC can also use labels as attributes but does not enforce mandatory, non-discretionary control.

64
MCQmedium

A financial services firm wants to let customers authorize a third-party budgeting application to read their account transaction history without sharing their banking password. Which technology should the firm deploy?

A.Remote Authentication Dial-In User Service (RADIUS)
B.Security Assertion Markup Language (SAML)
C.Kerberos
D.OAuth 2.0
AnswerD

OAuth 2.0 is an authorization framework that lets a resource owner grant a third-party application limited access to protected resources without sharing credentials. The budgeting app receives an access token scoped to reading transaction history, and the customer's banking password is never disclosed. This exactly matches the requirement for delegated, limited access to account data with user consent.

Why this answer

The scenario requires delegated authorization: a customer lets a third-party budgeting app read transaction history without revealing the banking password. OAuth 2.0 is built for this purpose, issuing scoped access tokens that the application presents to the resource server. The customer authenticates with the bank, approves specific scopes, and the app operates within those limits, so credentials are never shared and access can be revoked.

Exam trap

The trap here is confusing authentication with authorization and selecting SAML because it is a familiar federated identity standard, even though the requirement is delegated, scoped access rather than single sign-on.

65
Multi-Selecteasy

A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?

Select 2 answers
A.Roles can be organized in a hierarchy to inherit permissions
B.Users are assigned to roles based on their job functions
C.Access is controlled by the data owner
D.Permissions are assigned directly to users
E.Access decisions are based on subject and object attributes
AnswersA, B

Role hierarchies let senior roles inherit permissions from junior ones, so a manager role automatically gains the permissions assigned to the employee role beneath it. This satisfies RBAC's structural requirement that permissions attach to roles rather than individual users, reducing administrative overhead when many users share common access needs.

Why this answer

Option A is correct because RBAC supports role hierarchies, where a senior role (e.g., Manager) inherits the permissions of a junior role (e.g., Employee), which is a core RBAC capability for structuring permissions efficiently. Option B is correct because the defining characteristic of RBAC is assigning users to roles according to their job functions or responsibilities, and permissions are then granted to those roles rather than to individual users. Option C is incorrect because control by the data owner describes discretionary access control (DAC), not RBAC.

Option D is incorrect because assigning permissions directly to users is the opposite of RBAC, which assigns permissions to roles. Option E is incorrect because access decisions based on subject and object attributes describe attribute-based access control (ABAC), not RBAC.

Exam trap

SSCP often tests the distinction between RBAC (job-function roles and hierarchy), DAC (owner-controlled), MAC (labels/clearances), and ABAC (attributes) — candidates who confuse role hierarchy with attribute-based rules pick E or C.

66
MCQmedium

A company is implementing a biometric authentication system for physical access to a data center. The system must minimize false acceptances. Which metric is most directly related to false acceptance rate (FAR)?

A.Crossover error rate (CER)
B.Equal error rate (EER)
C.False rejection rate (FRR)
D.Threshold setting
AnswerD

The threshold determines how closely a biometric sample must match the stored template; a stricter threshold lowers FAR.

Why this answer

FAR is the rate at which an unauthorized person is incorrectly accepted. The threshold setting directly impacts FAR; a higher (more stringent) threshold reduces FAR but may increase FRR.

67
MCQeasy

A small business owner wants to implement access control for a shared file server. The owner wants each department manager to be able to decide which of their employees can access specific folders, without involving the IT department for every change. Which access control model is most appropriate for this requirement?

A.Mandatory access control (MAC)
B.Attribute-based access control (ABAC)
C.Discretionary access control (DAC)
D.Role-based access control (RBAC)
AnswerC

DAC allows resource owners to set permissions at their discretion, enabling department managers to control access to their folders without IT intervention. This matches the small business owner's requirement for delegated, flexible access control. DAC is simple to implement and commonly used in file systems, making it the most appropriate model here.

Why this answer

Discretionary access control (DAC) lets resource owners decide who can access their resources, which directly supports the requirement for department managers to control access to their folders without IT involvement. MAC, RBAC, and ABAC are more centralized or policy-driven and do not offer this level of delegated, owner-controlled discretion.

Exam trap

The trap here is assuming that any model allowing managers some control is DAC, when in fact only DAC gives resource owners full discretion to set permissions on their own resources.

68
MCQmedium

A security administrator at a financial firm is configuring access control for a new document management system. The system must enforce access decisions based on the sensitivity labels of documents and the clearance levels of employees, and it must prevent users from delegating their access to others. Which access control model should the administrator implement?

A.Discretionary access control (DAC)
B.Mandatory access control (MAC)
C.Attribute-based access control (ABAC)
D.Role-based access control (RBAC)
AnswerB

MAC enforces access based on security labels assigned to subjects and objects, and users cannot change or delegate these labels. This matches the requirement to use sensitivity labels and clearance levels while preventing delegation. The system, not the user, makes access decisions, ensuring strict confidentiality and integrity controls suitable for a financial firm.

Why this answer

Mandatory access control (MAC) is the only model that uses system-enforced labels for both subjects and objects, and it prohibits users from changing or delegating access. The scenario requires sensitivity labels, clearance levels, and no delegation, which are defining characteristics of MAC. DAC, RBAC, and ABAC do not provide these mandatory, non-delegable controls by default.

Exam trap

The trap here is assuming that any label-based or role-based model can enforce mandatory, non-delegable access, when only MAC uses system-controlled security labels that users cannot alter.

69
MCQmedium

A company deploys a RADIUS server for wireless 802.1X authentication. Users report that after a password change, their devices still authenticate successfully for several hours using cached credentials. Which RADIUS behavior most likely explains this?

A.RADIUS encrypts only the password field and relies on a shared secret, so cached credentials are replayed
B.The authenticator caches the successful authentication and continues to authorize the supplicant until reauthentication is triggered
C.RADIUS uses UDP and therefore cannot immediately propagate a password change to the client
D.The wireless controller performs local authentication and never contacts the RADIUS server
AnswerB

In 802.1X, the authenticator can maintain an authorized state for a supplicant after a successful RADIUS exchange and only reauthenticate at a configured interval or on a session event. Until reauthentication occurs, the device remains authorized even though the password changed. This caching of authorization state, governed by session and reauthentication timers, is the most likely reason users keep working for hours after the change.

Why this answer

In 802.1X, the authenticator keeps a supplicant in an authorized state after a successful RADIUS exchange and only reauthenticates at defined intervals or on session events. A password change does not tear down existing authorized sessions, so devices continue to work until reauthentication is forced. Transport protocol and local authentication do not explain the observed delay.

Exam trap

The trap here is blaming RADIUS transport or encryption for stale sessions, when the real cause is the authenticator caching an authorized state between reauthentications.

70
MCQmedium

An Identity Provider (IdP) sends an XML-based assertion to a Service Provider (SP) to grant access. Which federated identity standard is being used?

A.OAuth 2.0
B.Security Assertion Markup Language (SAML)
C.OpenID Connect (OIDC)
D.Kerberos
AnswerB

SAML exchanges authentication and authorisation data as XML assertions between an Identity Provider and a Service Provider. The stem's XML-based assertion from IdP to SP matches SAML's protocol exactly, unlike OAuth 2.0, which uses JSON access tokens rather than XML assertions.

Why this answer

SAML (Security Assertion Markup Language) is the standard that uses XML-based assertions to exchange authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP). The IdP sends a SAML assertion to the SP to grant access, which is exactly the scenario described.

Exam trap

The trap is confusing SAML with OAuth or OIDC; candidates may pick OAuth because it's commonly used for access delegation, but the exam expects recognition that XML-based assertions are the hallmark of SAML.

How to eliminate wrong answers

Option A is wrong because OAuth 2.0 is an authorization framework that uses tokens (typically JSON Web Tokens) for delegated access, not XML assertions for authentication. Option C is wrong because OpenID Connect (OIDC) is an authentication layer built on OAuth 2.0 that uses JSON Web Tokens (JWTs), not XML assertions. Option D is wrong because Kerberos is a network authentication protocol that uses tickets (not XML assertions) and is typically used within a single domain or realm, not for federated identity across organizations.

71
Multi-Selecthard

A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)

Select 3 answers
A.Identity Provider (IdP)
B.Trust relationship between IdP and SP
C.Ticket Granting Ticket (TGT)
D.Attribute Authority (AA)
E.Service Provider (SP)
AnswersA, B, E

The IdP authenticates users against the corporate Active Directory and issues signed SAML assertions to the SaaS relying party, satisfying the requirement that existing credentials be reused. Without it, no trusted authority exists to vouch for user identity, so federation cannot occur.

Why this answer

In a SAML-based federation, the Identity Provider (IdP) is essential because it is the entity that authenticates users against the corporate Active Directory and issues signed SAML assertions containing authentication and attribute statements (Option A). The Service Provider (SP) is equally essential as the SaaS application that consumes those SAML assertions to grant access, making it the relying party in the federation (Option E). A trust relationship between the IdP and SP is also required, since the SP must trust the IdP's signing certificate and the two parties exchange metadata (entityID, ACS URL, SSO URL, X.509 certificate) to validate assertions and establish the federation (Option B).

Option C is incorrect because a Ticket Granting Ticket is a Kerberos construct issued by a Key Distribution Center, not a SAML federation component. Option D is incorrect because an Attribute Authority is a separate SAML role that issues attribute assertions and is not one of the three essential components for basic SAML federation between an IdP and SP.

Exam trap

SSCP often mixes Kerberos components (TGT, KDC) into SAML questions — candidates who see 'ticket' and assume it belongs to federation pick the TGT, forgetting SAML uses assertions, not tickets.

72
Multi-Selecthard

A security auditor is evaluating a company's implementation of mandatory access control (MAC) using a commercial trusted operating system. The auditor needs to verify that the MAC implementation correctly enforces the no read up and no write down rules for confidentiality. Which TWO of the following are essential characteristics the auditor should confirm? (Choose two.)

Select 2 answers
A.Users can change the classification of objects they own.
B.Access decisions are based on the principle of least privilege.
C.Subjects with a lower clearance cannot read objects with a higher classification.
D.The system enforces a strict need-to-know policy for all users.
E.Subjects with a higher clearance cannot write to objects with a lower classification.
AnswersC, E

This is the no read up rule, a core principle of MAC for confidentiality. It ensures that a subject cannot access information above their clearance level, preventing unauthorized disclosure. The auditor must confirm this is enforced, as it is fundamental to MAC's confidentiality model and directly supports the no read up requirement.

Why this answer

The no read up rule prevents subjects from reading objects with higher classifications, and the no write down rule prevents subjects from writing to objects with lower classifications. These two rules are essential for enforcing confidentiality in MAC. The auditor must confirm that subjects with lower clearance cannot read higher-classified objects and that subjects with higher clearance cannot write to lower-classified objects.

Exam trap

The trap here is confusing general security principles like least privilege or need-to-know with the specific label-based rules that define MAC confidentiality, overlooking that only no read up and no write down are mandatory MAC characteristics.

73
MCQhard

In a federated identity scenario, a user authenticates to their home domain and accesses a resource in a partner domain. The partner domain trusts the authentication performed by the home domain. What is the home domain's role in this trust relationship?

A.Relying Party
B.Identity Provider (IdP)
C.Service Provider (SP)
D.Kerberos Distribution Center (KDC)
AnswerB

The home domain authenticates the user and issues the assertions the partner domain consumes, so it acts as the Identity Provider (IdP). The partner domain is the relying party or service provider that trusts those assertions.

Why this answer

In a federated identity trust, the home domain that authenticates the user and issues the security token is the Identity Provider (IdP). The partner domain that consumes that assertion and grants access is the Relying Party (or Service Provider). The IdP is trusted because it vouches for the user's identity.

Exam trap

The trap is the interchangeable-sounding terms Relying Party, Service Provider, and IdP — candidates must remember that the authenticating home domain is always the IdP, while the resource-owning partner domain is the RP/SP.

How to eliminate wrong answers

Option A is wrong because the Relying Party is the partner domain that accepts and relies on the token — the opposite side of the trust from the home domain. Option C is wrong because Service Provider is another name for the Relying Party in SAML/OIDC terminology, not the authenticating domain. Option D is wrong because a Kerberos Distribution Center is a component of Kerberos within a single realm that issues tickets; it is not the federated role played by the home domain in a cross-domain trust.

74
MCQmedium

An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?

A.Session recording
B.Just-in-time provisioning
C.Password vaulting
D.Role-based access control
AnswerB

Just-in-time provisioning grants elevated privileges only for the duration of a specific task, then automatically revokes them. This directly satisfies the PAM requirement for temporary, task-scoped access, eliminating standing privileges that attackers could exploit. Microsoft Entra ID Privileged Identity Management implements this through time-bound role activation, requiring justification and approval before elevation.

Why this answer

Just-in-time (JIT) provisioning in a PAM solution grants elevated privileges only for the duration of a specific task and then automatically revokes them, which is exactly the 'temporary elevated access' described. It minimizes standing privileges and reduces the attack surface. Other PAM features like vaulting and session recording support security but do not provide on-demand, time-bound elevation.

Exam trap

SSCP often tests the confusion between PAM features that control access (vaulting, JIT) and those that monitor it (session recording), leading candidates to choose a monitoring feature when the question asks for access provisioning.

How to eliminate wrong answers

Option A is wrong because session recording is an auditing/monitoring feature that captures privileged sessions for review — it does not grant temporary elevated access. Option C is wrong because password vaulting stores and rotates privileged credentials, but it does not itself provide time-bound elevation for a task. Option D is wrong because role-based access control (RBAC) assigns permissions based on roles, which are typically standing permissions, not temporary task-scoped elevation.

75
MCQhard

A defense contractor runs an air-gapped laboratory where removable media are used to move engineering data between isolated enclaves. Policy requires that a workstation be usable only when a specific approved removable device is inserted, and that the workstation become unusable the instant that device is removed. Which access control approach best enforces this behavior?

A.Implement a hardware token interlock that permits operation only while the approved device is physically engaged
B.Require multifactor authentication with a smart card before any user may log on to the workstation
C.Deploy a role-based policy that grants laboratory staff access to the enclave during working hours
D.Apply discretionary access control so that file owners may share engineering data only with vetted colleagues
AnswerA

A hardware interlock is a physical control that couples system operation to the presence of a specific object, so the workstation runs only with the approved device inserted and stops the moment it is withdrawn. This directly satisfies both halves of the policy without relying on software that could be bypassed.

Why this answer

The policy couples system availability to the physical presence of one approved object, which is a property of a hardware interlock rather than of any logical permission scheme. Interlocks act at the level of the machine itself, so the workstation cannot operate without the device and cannot continue operating after the device is removed, regardless of who is logged on.

Exam trap

The trap here is reaching for a strong logical control such as multifactor authentication when the requirement is actually about physical presence of a specific object.

Page 1 of 2 · 100 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Access Controls questions.