nerdexam
(ISC)2

SSCP · Question #146

Controls provide accountability for individuals who are accessing sensitive information. This accountability is accomplished:

The correct answer is A. through access control mechanisms that require identification and authentication and through. Option A is correct because *accountability requires knowing who did something, which is only possible when access control mechanisms enforce identification (declaring an identity) and authentication (proving that identity) - without both, you cannot trace actions back to a…

Submitted by luis.pe· Apr 18, 2026Access Controls

Question

Controls provide accountability for individuals who are accessing sensitive information. This accountability is accomplished:

Options

  • Athrough access control mechanisms that require identification and authentication and through
  • Bthrough logical or technical controls involving the restriction of access to systems and the
  • Cthrough logical or technical controls but not involving the restriction of access to systems and
  • Dthrough access control mechanisms that do not require identification and authentication and

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    5% (2)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Option A is correct because accountability requires knowing who did something, which is only possible when access control mechanisms enforce identification (declaring an identity) and authentication (proving that identity) - without both, you cannot trace actions back to a specific individual. Option B is wrong because restricting access to systems alone controls what can be accessed, but doesn't inherently create accountability for who accessed it. Option C compounds that flaw by additionally removing the restriction component, making it doubly insufficient for accountability. Option D is the direct opposite of the correct answer - skipping identification and authentication makes individual accountability impossible, since there's no verified identity to tie to an action.

Memory tip: Think "A = Accountability = Authentication" - the three A's. You can only hold someone accountable if you know who they are (identification) and verified it (authentication); access restriction alone is about authorization, not accountability.

Topics

#Accountability#Access Control#Identification#Authentication

Community Discussion

No community discussion yet for this question.

Full SSCP Practice