Final answer:
The true statement about profiles is that they control user password settings. Profiles do not grant access to all data, cannot revoke access, or directly grant access through record types.
Step-by-step explanation:
Among the statements about a profile in a user management system, the TRUE statement is that it controls user password settings. A profile typically defines a set of permissions and access settings for users. Contrarily to the other statements, profiles do not grant access to all data; that's generally controlled at a data sharing and permission level separate from object level permissions. Also, a profile cannot revoke access once it has been granted by sharing, as sharing rules and team access among other overrides function independently of profiles. Finally, record types help organize and control access to different page layouts and picklist values, but the ability to grant access to records is not exclusive to profiles and is paired with other organization-wide defaults, role hierarchies, and sharing settings.