nerdexam
(ISC)2

SSCP · Question #84

Which of the following access control models is based on sensitivity labels?

The correct answer is B. Mandatory access control. Access decisions are made based on the clearance of the subject and the sensitivity label of the Example: Eve has a "Secret" security clearance and is able to access the "Mugwump Missile Design Profile" because its sensitivity label is "Secret." She is denied access to the…

Submitted by the_admin· Apr 18, 2026Access Controls

Question

Which of the following access control models is based on sensitivity labels?

Options

  • ADiscretionary access control
  • BMandatory access control
  • CRule-based access control
  • DRole-based access control

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    90% (45)
  • C
    6% (3)
  • D
    2% (1)

Explanation

Access decisions are made based on the clearance of the subject and the sensitivity label of the Example: Eve has a "Secret" security clearance and is able to access the "Mugwump Missile Design Profile" because its sensitivity label is "Secret." She is denied access to the "Presidential Toilet Tissue Formula" because its sensitivity label is "Top Secret." The other answers are not correct because: Discretionary Access Control is incorrect because in DAC access to data is determined by the data owner. For example, Joe owns the "Secret Chili Recipe" and grants read access to Charles. Role Based Access Control is incorrect because in RBAC access decsions are made based on the role held by the user. For example, Jane has the role "Auditor" and that role includes read permission on the "System Audit Log." Rule Based Access Control is incorrect because it is a form of MAC. A good example would be a Firewall where rules are defined and apply to anyone connecting through the firewall.

Topics

#Access Control Models#Mandatory Access Control#Sensitivity Labels

Community Discussion

No community discussion yet for this question.

Full SSCP Practice