Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

Which of the following best describes the concept of accountability in access controls?

⚠ Common exam trap

SSCP often tests the distinction between authentication, authorization, and accountability — candidates frequently pick the authentication option (C) because it sounds like the 'security' answer, but accountability specifically requires unique identification plus logging, not just identity verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Users must be uniquely identified and their actions logged

Accountability in access control means that every action can be traced back to a uniquely identified individual, which requires both unique identification (no shared accounts) and logging of activity. This is what allows an organization to hold a specific person responsible for what was done with their credentials. It is distinct from authentication (proving identity) and authorization (what you're allowed to do).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Users must present multiple factors to gain access

    Why it's wrong here

    Presenting multiple factors is multi-factor authentication, which strengthens identity verification at login. Accountability concerns attributing actions after the fact via unique identities and audit logs, not the number of credentials presented. MFA would be the answer if the question asked how to increase assurance in authentication strength.

  • ✓

    Users must be uniquely identified and their actions logged

    Why this is correct

    Accountability requires that each user be uniquely identified so actions can be traced back to a specific individual, with those actions recorded in logs. Shared or generic accounts break this, since activity cannot be attributed to one person.

  • ✗

    The system must verify the user's identity before granting access

    Why it's wrong here

    Verifying identity before granting access describes authentication, the process of confirming a claimed identity. Accountability instead requires that authenticated actions be traceable to that identity through logging and non-repudiation. Authentication would be correct if the question asked how a system confirms who a user is before access.

  • ✗

    The resource owner can delegate access to others

    Why it's wrong here

    Delegation transfers permissions from a resource owner to another principal; it says nothing about tracing actions back to an individual. Accountability requires that each action be attributable to a unique subject through logging and audit trails. Delegation would be relevant when designing authorisation models, not when defining accountability.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.