mediumMultiple Select
SSCP Practice Question: Which TWO of the following are characteristics of…
Which TWO of the following are characteristics of mandatory access control (MAC)?
⚠ Common exam trap
Many exam-takers confuse MAC with DAC, mistakenly thinking that MAC allows users to set permissions or that it is common in commercial environments, when in fact MAC is policy-driven and used in high-security contexts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system enforces access decisions based on policies
Option A is correct because MAC is defined by policy-driven enforcement: the operating system or security kernel makes access decisions according to centrally administered rules (e.g., Bell-LaPadula or Biba models), not user choice. Option B is correct because MAC relies on security labels (sensitivity levels and categories) attached to both subjects and objects, and access is granted only when the subject's label dominates the object's label per the policy. Option C is incorrect because basing access on the user's discretion describes discretionary access control (DAC), where owners set permissions. Option D is incorrect because MAC is most commonly associated with high-assurance government, military, and intelligence environments rather than typical commercial settings. Option E is incorrect because in MAC users cannot delegate or grant access to others; only the policy administrator can change labels and authorizations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The system enforces access decisions based on policies
Why this is correct
MAC decisions are enforced by the operating system against a central policy, not by object owners' discretion. The stem's policy-based enforcement is the defining characteristic: subjects cannot override or delegate access, distinguishing MAC from discretionary models.
- ✓
Security labels are assigned to subjects and objects
Why this is correct
In MAC, every subject and object carries a security label, such as classification or clearance, and the system compares them to decide access. The stem's labelling requirement is intrinsic to MAC because authorisation derives from label relationships rather than owner discretion.
- ✗
Access decisions are based on the user’s discretion
Why it's wrong here
MAC decisions derive from system-assigned labels and clearances compared by the operating system, never from the user's own judgement; discretion is the defining property of DAC. It is tempting because users still authenticate and select sessions under MAC, but that is not the same as deciding which objects they may access.
- ✗
It is commonly used in commercial environments
Why it's wrong here
MAC is implemented in environments demanding strict, centrally enforced confidentiality, such as government, military and high-assurance systems, not ordinary commercial deployments where DAC dominates. It is tempting because commercial organisations do deploy mandatory controls in niche regulated cases, but that is the exception rather than the defining characteristic.
- ✗
Users can grant access to other users
Why it's wrong here
Under MAC, only the security administrator can alter labels or clearances; users cannot pass their access rights to others, which is instead a DAC capability via ownership and ACL modification. It is tempting because delegation exists in many access-control models, but MAC deliberately removes it to preserve central enforcement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.