SSCP Access Controls Practice Question
Which of the following best describes the concept of accountability in access controls?
⚠ Common exam trap
SSCP often tests the distinction between authentication, authorization, and accountability — candidates frequently pick the authentication option (C) because it sounds like the 'security' answer, but accountability specifically requires unique identification plus logging, not just identity verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Users must be uniquely identified and their actions logged
Accountability in access control means that every action can be traced back to a uniquely identified individual, which requires both unique identification (no shared accounts) and logging of activity. This is what allows an organization to hold a specific person responsible for what was done with their credentials. It is distinct from authentication (proving identity) and authorization (what you're allowed to do).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Users must present multiple factors to gain access
Why it's wrong here
Presenting multiple factors is multi-factor authentication, which strengthens identity verification at login. Accountability concerns attributing actions after the fact via unique identities and audit logs, not the number of credentials presented. MFA would be the answer if the question asked how to increase assurance in authentication strength.
- ✓
Users must be uniquely identified and their actions logged
Why this is correct
Accountability requires that each user be uniquely identified so actions can be traced back to a specific individual, with those actions recorded in logs. Shared or generic accounts break this, since activity cannot be attributed to one person.
- ✗
The system must verify the user's identity before granting access
Why it's wrong here
Verifying identity before granting access describes authentication, the process of confirming a claimed identity. Accountability instead requires that authenticated actions be traceable to that identity through logging and non-repudiation. Authentication would be correct if the question asked how a system confirms who a user is before access.
- ✗
The resource owner can delegate access to others
Why it's wrong here
Delegation transfers permissions from a resource owner to another principal; it says nothing about tracing actions back to an individual. Accountability requires that each action be attributable to a unique subject through logging and audit trails. Delegation would be relevant when designing authorisation models, not when defining accountability.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.