nerdexam
(ISC)2

SSCP · Question #90

Which access control model is best suited in an environment where a high security level is required and where it is desired that only the administrator grants access control?

The correct answer is B. MAC. MAC provides high security by regulating access based on the clearance of individual users and sensitivity labels for each object. Clearance levels and sensitivity levels cannot be modified by individual users -- for example, user Joe (SECRET clearance) cannot reclassify the "Pre

Submitted by andreas_gr· Apr 18, 2026Access Controls

Question

Which access control model is best suited in an environment where a high security level is required and where it is desired that only the administrator grants access control?

Options

  • ADAC
  • BMAC
  • CAccess control matrix
  • DTACACS

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    85% (41)
  • C
    2% (1)
  • D
    8% (4)

Explanation

MAC provides high security by regulating access based on the clearance of individual users and sensitivity labels for each object. Clearance levels and sensitivity levels cannot be modified by individual users -- for example, user Joe (SECRET clearance) cannot reclassify the "Presidential Doughnut Recipe" from "SECRET" to "CONFIDENTIAL" so that his friend Jane (CONFIDENTIAL clearance) can read it. The administrator is ultimately responsible for configuring this protection in accordance with security policy and directives from the Data Owner. DAC is incorrect. In DAC, the data owner is responsible for controlling access to the object. Access control matrix is incorrect. The access control matrix is a way of thinking about the access control needed by a population of subjects to a population of objects. This access control can be applied using rules, ACL's, capability tables, etc. TACACS is incorrect. TACACS is a tool for performing user authentication.

Topics

#Access Control Models#Mandatory Access Control (MAC)#Security Levels#Centralized Access Control

Community Discussion

No community discussion yet for this question.

Full SSCP Practice