
Systems Security Certified Practitioner
Domain 2Objective 4
2.4 - Understand and Administer Access Controls SSCP Practice Questions (Page 1)
Part of the Access Controls domain, which accounts for 15% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 17 practice questions to prepare you well beyond it. (estimate)
17questions here
4free pages
6concepts
15%of the exam
Questions 1–5
- 1
A hospital is implementing an electronic health record (EHR) system. Nurses need to view and update patient records for patients assigned to their ward. Physicians need to view records for all patients in the hospital but only update records for patients they are actively treating. Lab technicians need read-only access to records for patients with pending lab orders. The compliance officer insists that access decisions must be based on the staff member's job function, not on individual user preferences or object ownership. Which access control model should the hospital implement?
Select an answer first - 2
A cloud storage provider needs to grant access to a document based on multiple factors: the user's department, the document's sensitivity level, and whether the user is accessing from a trusted corporate device. The policy must be evaluated dynamically at the time of each access request. Which access control model is best suited for this requirement?
Select an answer first - 3
In Role-Based Access Control (RBAC), how is access to a resource typically determined?
Select an answer first - 4
In a system implementing Mandatory Access Control (MAC), which entity is responsible for making the final access decision?
Select an answer first - 5
A defense contractor processes documents classified as CONFIDENTIAL and SECRET. The security policy states that a user with a SECRET clearance can read SECRET and CONFIDENTIAL documents, but a user with only CONFIDENTIAL clearance cannot read SECRET documents. The system must enforce this policy centrally, and users must not be able to change the classification of a document or grant access to another user. Which access control model enforces this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.