Be able to calculate effective permissions for a user given NTFS and share permissions, group memberships, and inheritance settings. The most important thing: explicit deny always wins, and effective access is the intersection of share and NTFS permissions.
Start practicing
Windows Access Controls — choose a session length
Free · No account required
Domain overview
This domain covers Windows access control mechanisms: NTFS permissions, share permissions, Active Directory security groups, and access tokens. You must analyze effective permissions, inheritance, and explicit denies. Questions present scenarios about users in multiple groups, requiring you to determine resulting access or configure permissions to meet a requirement.
Exam objectives
NTFS permissions and inheritance, including explicit deny and disabling inheritance.
Access token generation during logon, containing user SID and group SIDs.
Effective permissions calculation when a user belongs to multiple groups.
Share permissions vs NTFS permissions and how they combine for network access.
Forgetting that explicit deny overrides all allow permissions, even if the user is in a group that allows access.
Assuming share permissions are evaluated the same as NTFS; they combine to give the most restrictive effective access.
Overlooking that disabling inheritance can convert inherited permissions to explicit or remove them entirely.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?
2Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?
3Which Windows feature allows for fine-grained access control based on user attributes like department or project code rather than just security groups?
4A security analyst is reviewing file server permissions and notices that a user, Elena, has the 'Modify' permission on a folder via group membership in 'Project_X', but she is also a member of the 'Contractors' group, which has an explicit 'Deny' for 'Write'. Elena reports she cannot edit any files in the folder. What is the most likely explanation for this behavior?
5A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?
6A security analyst is investigating a Windows Server 2019 file server where a user named Alice reports she cannot open a file in a shared folder even though she is a member of a group that has 'Modify' permission on that file. The analyst runs 'icacls' and sees that Alice's user account has an explicit 'Deny' entry for 'Read & execute' on the file. What is the most likely reason Alice cannot access the file?
7A junior administrator is setting up a shared folder on a Windows Server 2022 member server. The folder will be accessed by a group called 'SalesTeam'. The administrator wants to ensure that members of SalesTeam can read and write files, but cannot change permissions or take ownership. Which NTFS permission should the administrator assign to the SalesTeam group?
8A security consultant is reviewing a Windows Server 2019 file server. The folder C:\Projects has a DACL that includes an entry for the group 'Contractors' with the following advanced permissions: 'List folder / read data', 'Read attributes', 'Read extended attributes', 'Read permissions', and 'Synchronize'. The consultant notices that a contractor user can open and read files in the folder but cannot create new files or modify existing ones. Which access control concept best explains this behavior?
9A security administrator is reviewing the access control model used by a Windows Server 2022 domain controller. They need to ensure that when a user logs on, the system evaluates the user's group memberships and generates a data structure that is used for all subsequent access checks. Which component is responsible for this?
10An administrator is configuring NTFS permissions on a folder named C:\Audit. The folder currently has inheritance enabled from C:\, which grants Users Read & Execute. The administrator wants to prevent members of the group Temp_Contractors from accessing the folder, but they must still be able to access other folders on the C: drive. The administrator adds an explicit Deny Full Control permission for Temp_Contractors on C:\Audit. What is the effect of this change?
Be able to calculate effective permissions for a user given NTFS and share permissions, group memberships, and inheritance settings. The most important thing: explicit deny always wins, and effective access is the intersection of share and NTFS permissions.
The Courseiva GSEC question bank contains 10 questions in the Windows Access Controls domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Windows Access Controls domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included