TechNuggets Academy

Access Controls Concepts

Free ISC2 Certified in Cybersecurity practice — 6 questions on Access Controls Concepts, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: Access Controls Concepts
A boutique software company allows each employee who creates a project file to personally decide which specific colleagues can view, edit, or share that file, and the creator can add or remove those permissions at any time without going through IT. Which access control model does this describe?
DAC lets the resource owner (the file creator) control access permissions at their own discretion, including granting or revoking access at will.
Question 2 of 6 · Domain 3: Access Controls Concepts
A data center's server room entrance consists of two consecutive interlocking doors. Only one door can be unlocked at a time, and the second door will not open until the first is fully closed and a badge plus PIN are verified. This design is intended to stop an unauthorized person from slipping in behind an authorized employee. What is this control called?
A mantrap uses two interlocking doors where only one opens at a time, physically preventing tailgating/piggybacking into a secure area.
Question 3 of 6 · Domain 3: Access Controls Concepts
In the identification-authentication-authorization-accountability chain, which set of controls is MOST directly responsible for ensuring accountability?
Accountability means being able to tie specific actions to a specific individual, which requires unique identifiers, comprehensive audit trails, and non-repudiation mechanisms such as digital signatures so the action cannot be denied later.
Question 4 of 6 · Domain 3: Access Controls Concepts
To enforce segregation of duties for application deployments, which configuration should an organization implement?
Segregation of duties requires splitting critical tasks—writing, approving, and deploying code—among different individuals so that no single person can push unreviewed or unauthorized changes into production.
Question 5 of 6 · Domain 3: Access Controls Concepts
A defense agency labels every document with a classification level (Top Secret, Secret, Confidential) and only permits access when a user's security clearance—assigned centrally by the agency's security office—is equal to or higher than the document's classification, regardless of the document creator's preference. Which access control model is being used?
MAC compares a centrally-assigned subject clearance level against an object's classification label to make access decisions, independent of the document owner's wishes—this is the classic MAC example tested on the exam.
Question 6 of 6 · Domain 3: Access Controls Concepts
An airport's fingerprint-based access control system is rejecting too many legitimate employees, causing long lines at the secure entrance. Security administrators lower the sensitivity threshold of the scanner to reduce these rejections. What is the MOST likely security consequence of this change?
Lowering a biometric scanner's sensitivity threshold reduces false rejections but trades off by increasing the False Acceptance Rate, meaning unauthorized individuals are more likely to be incorrectly granted access.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code SECPREP34 — valid through Oct 11.

Get my $34.99 deal →