SSCP Access Controls Practice Question
Which access control model allows the owner of a resource to grant permissions to others?
⚠ Common exam trap
The trap is confusing 'owner grants permissions' with RBAC or ABAC; candidates often pick RBAC because it sounds like delegated administration, but only DAC explicitly places grant authority with the resource owner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Discretionary Access Control (DAC)
Discretionary Access Control (DAC) is defined by the owner of an object having the discretion to grant or revoke access to other subjects, typically via ACLs on files or resources. This owner-controlled permission model is the defining characteristic of DAC, as opposed to MAC where the system enforces labels and RBAC where roles determine access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Discretionary Access Control (DAC)
Why this is correct
Discretionary Access Control satisfies the stem's requirement because the resource owner holds discretion over permissions, typically via access control lists, and can pass that authority to other subjects. Unlike mandatory or role-based models, DAC permits owner-initiated delegation, directly matching the scenario where an owner grants permissions to others.
- ✗
Attribute-Based Access Control (ABAC)
Why it's wrong here
ABAC evaluates subject, resource and environmental attributes against policies, so permission derives from policy evaluation rather than owner discretion. It is tempting because it is highly granular and dynamic, and ABAC would be correct where access decisions depend on contextual conditions such as time, location or device posture.
- ✗
Mandatory Access Control (MAC)
Why it's wrong here
MAC enforces access through system-wide labels and clearances set by a central authority, leaving no discretion to resource owners. It is tempting because it provides strong containment for classified data, and MAC would be correct in environments such as government or military systems requiring hierarchical confidentiality labels.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
RBAC assigns permissions through organisational roles rather than resource ownership, so no owner grants access. It is tempting because roles scale administration across many users, and RBAC would be correct where access derives from job function, such as all nurses accessing the same patient records.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.