220-1102 Security Practice Question
A user reports that they cannot access a shared folder. The user is a member of the 'Sales' group. The NTFS permissions allow 'Sales' group 'Read', and the share permissions allow 'Everyone' 'Full Control'. What is the user's effective access?
⚠ Common exam trap
Watch out — candidates often assume the least restrictive permission (Full Control from share) applies, forgetting that NTFS permissions act as a secondary filter and the effective permission is the more restrictive of the two.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read
When determining effective access for a shared folder, Windows combines NTFS permissions and share permissions by taking the most restrictive of the two. Here, the share permissions grant 'Everyone' 'Full Control', but the NTFS permissions grant the 'Sales' group 'Read'. The effective permission is the more restrictive of the two, which is 'Read'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Read
Why this is correct
The effective permission is determined by the most restrictive of the NTFS permission and the share permission. Here, the user has Read at the NTFS level and Full Control at the share level, so the intersection is Read. Share Full Control only authorizes what NTFS also allows; since NTFS grants only Read, the user can list and view files but cannot modify or delete them. Therefore, Read is correct.
- ✗
Full Control
Why it's wrong here
Full Control is possible only if both NTFS and share permissions grant Full Control (or at least the required rights). In this scenario, the share grants Full Control, but the NTFS permission is limited to Read, so the effective permission cannot exceed Read. The cumulative effect is the least permissive of the two, meaning the user lacks the Write, Modify, and Delete rights that Full Control would provide. Thus, Full Control is not the effective permission.
- ✗
No access
Why it's wrong here
No access would occur if either the NTFS permission or the share permission explicitly denied access, or if the user had no permissions at all. Here, the user is a member of a group with NTFS Read and the share grants Full Control, so the user has at least read-level access to the shared folder. Since the effective permission is Read, the user can open and view contents, so 'No access' is incorrect.
- ✗
Modify
Why it's wrong here
Modify is a higher-level permission that includes Read, Write, Execute, and Delete. Although the share permission grants Full Control, the NTFS permission restricts the user to Read only, so the effective permission cannot include Write or Delete. The final effective permission is the most restrictive combination, which is Read, not Modify. Therefore, Modify is not available to the user.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
NTFS
NTFS (New Technology File System) is a file system used by Windows to organize and control how data is stored, retrieved, and secured on a hard drive or SSD.
Key term
Folder
A folder is a logical container used to organize and group digital files, resources, or cloud-based assets within a system or platform.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.