ExamQuestions.com

Register
Login
System Security Certified Practitioner (SSCP) Exam Questions

ISC

System Security Certified Practitioner (SSCP)

108 / 610

Question 108:

Which of the following statements pertaining to access control is false? 

Answer options:

A. Users should only access data on a need-to-know basis.
B. If access is not explicitly denied, it should be implicitly allowed.
C. Access rights should be granted based on the level of trust a company has on a subject.
D. Roles can be an efficient way to assign rights to a type of user who performs certain tasks.