
GIAC Critical Controls Certification
Domain 3Objective 1
Access Control Management GCCC Practice Questions (Page 8)
Part of the Access and Identity Management domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 36–40
- 36
In which access control model does the owner of a resource decide who can access it and what privileges they receive?
Select an answer first - 37
An organization is implementing multi-factor authentication (MFA) for remote access. The security team wants to use a method that is resistant to phishing and does not require additional hardware. Which authentication method best meets these requirements?
Select an answer first - 38
A company wants to allow its employees to use their existing corporate credentials to access a third-party SaaS application. The company uses an identity provider (IdP) that supports SAML 2.0. Which approach should be implemented?
Select an answer first - 39
An organization uses an attribute-based access control (ABAC) system. A user requests access to a document. The policy engine evaluates the user's department, the document's classification label, and the current time. What is the primary purpose of this evaluation?
Select an answer first - 40
Which account lifecycle activity involves periodically reviewing user access rights to ensure they are still appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.