nerdexam
(ISC)2

SSCP · Question #146

Controls provide accountability for individuals who are accessing sensitive information. This accountability is accomplished:

The correct answer is A. through access control mechanisms that require identification and authentication and through. Option A is correct because *accountability requires knowing who did something, which is only possible when access control mechanisms enforce identification (declaring an identity) and authentication (proving that identity) - without both, you cannot trace actions back to a speci

Submitted by luis.pe· Apr 18, 2026Access Controls

Question

Controls provide accountability for individuals who are accessing sensitive information. This accountability is accomplished:

Options

  • Athrough access control mechanisms that require identification and authentication and through
  • Bthrough logical or technical controls involving the restriction of access to systems and the
  • Cthrough logical or technical controls but not involving the restriction of access to systems and
  • Dthrough access control mechanisms that do not require identification and authentication and

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    5% (2)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Option A is correct because accountability requires knowing who did something, which is only possible when access control mechanisms enforce identification (declaring an identity) and authentication (proving that identity) - without both, you cannot trace actions back to a specific individual. Option B is wrong because restricting access to systems alone controls what can be accessed, but doesn't inherently create accountability for who accessed it. Option C compounds that flaw by additionally removing the restriction component, making it doubly insufficient for accountability. Option D is the direct opposite of the correct answer - skipping identification and authentication makes individual accountability impossible, since there's no verified identity to tie to an action.

Memory tip: Think "A = Accountability = Authentication" - the three A's. You can only hold someone accountable if you know who they are (identification) and verified it (authentication); access restriction alone is about authorization, not accountability.

Topics

#Accountability#Access Control#Identification#Authentication

Community Discussion

No community discussion yet for this question.

Full SSCP Practice