Courseiva
mediumMultiple Select

SSCP Practice Question: Which TWO of the following are characteristics of…

Which TWO of the following are characteristics of mandatory access control (MAC)?

⚠ Common exam trap

Many exam-takers confuse MAC with DAC, mistakenly thinking that MAC allows users to set permissions or that it is common in commercial environments, when in fact MAC is policy-driven and used in high-security contexts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The system enforces access decisions based on policies

Option A is correct because MAC is defined by policy-driven enforcement: the operating system or security kernel makes access decisions according to centrally administered rules (e.g., Bell-LaPadula or Biba models), not user choice. Option B is correct because MAC relies on security labels (sensitivity levels and categories) attached to both subjects and objects, and access is granted only when the subject's label dominates the object's label per the policy. Option C is incorrect because basing access on the user's discretion describes discretionary access control (DAC), where owners set permissions. Option D is incorrect because MAC is most commonly associated with high-assurance government, military, and intelligence environments rather than typical commercial settings. Option E is incorrect because in MAC users cannot delegate or grant access to others; only the policy administrator can change labels and authorizations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The system enforces access decisions based on policies

    Why this is correct

    MAC decisions are enforced by the operating system against a central policy, not by object owners' discretion. The stem's policy-based enforcement is the defining characteristic: subjects cannot override or delegate access, distinguishing MAC from discretionary models.

  • ✓

    Security labels are assigned to subjects and objects

    Why this is correct

    In MAC, every subject and object carries a security label, such as classification or clearance, and the system compares them to decide access. The stem's labelling requirement is intrinsic to MAC because authorisation derives from label relationships rather than owner discretion.

  • ✗

    Access decisions are based on the user’s discretion

    Why it's wrong here

    MAC decisions derive from system-assigned labels and clearances compared by the operating system, never from the user's own judgement; discretion is the defining property of DAC. It is tempting because users still authenticate and select sessions under MAC, but that is not the same as deciding which objects they may access.

  • ✗

    It is commonly used in commercial environments

    Why it's wrong here

    MAC is implemented in environments demanding strict, centrally enforced confidentiality, such as government, military and high-assurance systems, not ordinary commercial deployments where DAC dominates. It is tempting because commercial organisations do deploy mandatory controls in niche regulated cases, but that is the exception rather than the defining characteristic.

  • ✗

    Users can grant access to other users

    Why it's wrong here

    Under MAC, only the security administrator can alter labels or clearances; users cannot pass their access rights to others, which is instead a DAC capability via ownership and ACL modification. It is tempting because delegation exists in many access-control models, but MAC deliberately removes it to preserve central enforcement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.