nerdexam
(ISC)2

SSCP · Question #938

What security model implies a central authority that define rules and sometimes global rules, dictating what subjects can have access to what objects?

The correct answer is D. Non-discretionary access control. As a security administrator you might configure user profiles so that users cannot change the system's time, alter system configuration files, access a command prompt, or install unapproved applications. This type of access control is referred to as nondiscretionary, meaning…

Submitted by renata2k· Apr 18, 2026Access Controls

Question

What security model implies a central authority that define rules and sometimes global rules, dictating what subjects can have access to what objects?

Options

  • AFlow Model
  • BDiscretionary access control
  • CMandatory access control
  • DNon-discretionary access control

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    7% (4)
  • C
    2% (1)
  • D
    88% (49)

Explanation

As a security administrator you might configure user profiles so that users cannot change the system's time, alter system configuration files, access a command prompt, or install unapproved applications. This type of access control is referred to as nondiscretionary, meaning that access decisions are not made at the discretion of the user. Nondiscretionary access controls are put into place by an authoritative entity (usually a security administrator) with the goal of protecting the organization's most critical assets. Non-discretionary access control is when a central authority determines what subjects can have access to what objects based on the organizational security policy. Centralized access control is not an existing security model. Both, Rule Based Access Control (RuBAC or RBAC) and Role Based Access Controls (RBAC) falls into this category.

Topics

#Access control models#Non-discretionary access control#Centralized access management#Security policies

Community Discussion

No community discussion yet for this question.

Full SSCP Practice