Free Systems Security Certified Practitioner practice — 6 questions on Access Controls, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 2: Access Controls
A financial institution requires that no single employee can both create a vendor record and approve payments to that vendor. Which access control principle is being enforced?
Separation of duties splits a critical business process across multiple people so that no single individual can complete an entire fraud-prone transaction alone (create vendor + approve payment).
Question 2 of 6 · Domain 2: Access Controls
A cloud application receives a SAML assertion from an external identity provider containing attributes such as department=Finance and clearance=Confidential, and the application's policy engine evaluates these attributes at request time to grant or deny access dynamically. Which access control model is being used?
ABAC evaluates multiple subject, resource, and environmental attributes against policy rules at access-decision time, exactly as described with department and clearance attributes from the federated assertion.
Question 3 of 6 · Domain 2: Access Controls
An organization implements Kerberos authentication for internal resource access. Users intermittently fail authentication with ticket validation errors, and investigation shows the errors correlate with slight time differences between client workstations and the Key Distribution Center. Which configuration setting is MOST likely the root cause?
Kerberos relies on timestamps to prevent replay attacks; tickets are rejected if the client and KDC clocks differ by more than the configured skew tolerance (commonly a default of around 5 minutes), so a tolerance set too small causes valid tickets from slightly-out-of-sync clients to fail.
Question 4 of 6 · Domain 2: Access Controls
An organization needs a mandatory access control model that primarily prevents unauthorized modification of data, where a subject can write only to objects at or below its own integrity level and can read only objects at or above its own integrity level. Which model does this describe?
The Biba model enforces 'no read down' and 'no write up' to protect data integrity: subjects read only at or above their integrity level and write only at or below it, preventing low-integrity data from corrupting high-integrity data.
Question 5 of 6 · Domain 2: Access Controls
An employee resigns effective immediately during a contentious exit meeting. Following identity lifecycle management best practices, what should the security team do FIRST?
Immediate deprovisioning — disabling accounts and revoking credentials — is the highest priority action to prevent unauthorized access from a departing, potentially disgruntled employee; all other administrative tasks follow after access is secured.
Question 6 of 6 · Domain 2: Access Controls
A company is deploying a multi-tenant cloud application where access decisions must consider real-time context such as user location, device compliance status, time of day, and resource sensitivity, scaling to thousands of dynamically changing users and resources without requiring new role definitions for every new combination. Which access control model BEST meets these requirements?
ABAC evaluates combinations of subject, resource, and environmental attributes (location, device state, time, sensitivity) at request time via policy rules, scaling naturally without the role explosion that occurs when RBAC tries to model every contextual combination.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.