Courseiva

SSCP · topic practice

Access Controls practice questions

Access Controls covers how subjects are identified, authenticated, authorized, and deprovisioned across the account lifecycle. SSCP questions test model selection (MAC, DAC, RBAC, ABAC), authentication factors and one-time passwords, least privilege, separation of duties, and the correct order of termination actions such as disabling accounts before removing access.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Access Controls

What the exam tests

What to know about Access Controls

Be able to map a scenario to the right access control model, authentication factor, or lifecycle step, and state the action order. The single most important thing: on termination, disable the account first, then remove or transfer access and data before deletion.

Distinguishing MAC, DAC, RBAC, and ABAC based on how permissions are assigned

Selecting authentication factors: something you know, have, or are

Ordering account lifecycle steps: provisioning, review, and deprovisioning on termination

Applying least privilege, need to know, and separation of duties controls

Watch out for

Common Access Controls exam traps

  • ▸Confusing MAC with DAC: MAC uses labels and clearances, while DAC lets the object owner set permissions.
  • ▸Deleting a terminated user's account before disabling it, losing audit trail and risking residual access.
  • ▸Treating RBAC as clearance-based; RBAC assigns permissions through roles, not subject clearance versus object classification.

Practice set

Access Controls questions

20 questions · select your answer, then reveal the explanation

A security engineer is designing a system that must ensure data integrity at all costs, even if it means sacrificing availability. Which access control model and corresponding principle should be applied?

An organization is planning to implement a Single Sign-On (SSO) solution. Which THREE of the following are commonly associated with SSO technologies?

A security auditor is reviewing the account lifecycle process. Which TWO of the following are mandatory steps during the deprovisioning (offboarding) process?

Which authentication method uses a time-based one-time password (TOTP) generated by a hardware or software token?

Question 5mediummultiple choice
Read the full Access Controls explanation →

An organization implements RBAC to enforce separation of duties. Which of the following is a key benefit of using role-based access control in this context?

During a security audit, it is discovered that a service account has been used to log in interactively to a server. The account was originally provisioned only for running a background service. Which PAM (Privileged Access Management) control would best prevent such misuse in the future?

A security architect is designing an access control system for a healthcare application that requires fine-grained access decisions based on user role, location, time of day, and patient consent. Which TWO access control models are best suited for this requirement?

Question 8mediummultiple choice
Read the full Access Controls explanation →

An organization uses Kerberos for single sign-on (SSO) within its Windows domain. Which component issues ticket-granting tickets (TGTs) after verifying user credentials?

Question 9mediummultiple choice
Read the full Access Controls explanation →

A security administrator is configuring a system to enforce separation of duties. In which access control model is this principle most directly implemented?

A company wants to implement multi-factor authentication (MFA) for remote access. Which THREE of the following are examples of different authentication factors? (Choose THREE.)

Question 11hardmultiple choice
Read the full Access Controls explanation →

A security analyst notices that a user's account was used to access sensitive files after the user had left the company. Which access control principle was most likely violated?

Question 12mediummultiple choice
Read the full Access Controls explanation →

In Role-Based Access Control (RBAC), what is the purpose of role hierarchy?

An organization is planning to implement multi-factor authentication. Which TWO of the following are valid authentication factors?

A security administrator is designing an identity federation solution. Which THREE of the following are commonly used federation standards?

A security analyst is investigating an account compromise. The organization uses Kerberos for single sign-on. Which TWO of the following would help in tracking the source of the compromise?

A security engineer is designing a federated identity solution for cross-domain authentication. Which THREE of the following technologies are commonly used?

Question 17mediummultiple choice
Read the full Access Controls explanation →

A security administrator is reviewing access logs and notices that a user was able to access a file after only providing a username and password, even though the file contains highly sensitive data. The organization's policy requires that access to sensitive files be based on the user's job role and that users should not have direct control over permissions. Which access control model is most likely in use, and what is the primary weakness?

A security administrator is designing an attribute-based access control (ABAC) policy for a cloud environment. The policy must evaluate multiple types of attributes to make access decisions. Which TWO of the following are categories of attributes that ABAC typically evaluates? (Choose two.)

Question 19hardmultiple choice
Read the full Access Controls explanation →

An administrator is configuring a Linux server and wants file access to be governed by the permissions of the directory in which the file resides, rather than by the file's own permission bits. Which permission should the administrator apply to the directory to achieve this behavior?

Question 20mediummultiple choice
Read the full Access Controls explanation →

A financial services firm runs a quarterly access review. The security team discovers that a payroll administrator can also approve vendor invoices in the ERP system, and that the same individual can modify their own expense reimbursements. The CISO asks which access control principle is being violated so it can be documented as a finding.

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Access Controls sessions

Start a Access Controls only practice session

Every question in these sessions is drawn from the Access Controls domain — nothing else.

Related practice questions

Related SSCP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SSCP exam test about Access Controls?
Be able to map a scenario to the right access control model, authentication factor, or lifecycle step, and state the action order. The single most important thing: on termination, disable the account first, then remove or transfer access and data before deletion.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Access Controls questions in a focused session?
Yes — the session launcher on this page draws every question from the Access Controls domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SSCP topics?
Use the topic links above to move to related areas, or go back to the SSCP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SSCP exam covers. They are not copied from any real exam or dump site.