
Certified Information Systems Security Professional
Domain 5Objective 4
5.4 - Implement and Manage Authorization Mechanisms CISSP Practice Questions (Page 3)
Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
13%of the exam
Questions 11–15
- 11
In Role-Based Access Control (RBAC), what is the primary factor that determines the permissions a user receives?
Select an answer first - 12
A company wants to allow employees to access the building's Wi-Fi only during business hours (9 AM to 5 PM) and only from within the office. Which access control model best fits this requirement?
Select an answer first - 13
Which mechanism is commonly used to implement Discretionary Access Control (DAC)?
Select an answer first - 14
A financial services firm wants to restrict access to its trading application based on the user's IP address and the time of day. The security team needs a solution that evaluates these conditions dynamically for each access request and can be updated without modifying the application code. Which access control approach best meets this requirement?
Select an answer first - 15
A financial institution is implementing a risk-based access control system. The system must allow a user to perform a high-value transaction if the risk score is below a threshold, but require step-up authentication if the risk score is above the threshold. The institution also wants to ensure that the risk score is calculated consistently across all access requests. Which architecture is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.