shieldCISSP Practice Domain 5 — Identity and Access Management (IAM) Q85 of 120

Which access control model labels both subjects and objects with classification levels and enforces non-discretionary rules?

A CISSP practice question covering Domain 5: Identity and Access Management (IAM). Try answering before reading the explanation below.

Show options & answer
A
DAC
B
MAC
✓ Correct answer
C
RBAC
D
ABAC
Why "MAC" is the right answer

MAC (Mandatory Access Control) enforces fixed labels (Top Secret, Secret, etc.) — used in military and government systems. DAC lets owners grant access at their discretion. RBAC uses roles. ABAC uses arbitrary attributes.

Study videos for this topic

Want to go deeper on Domain 5? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →