Courseiva
Security →easyMultiple Choice

FC0-U71 Security Practice Question

A small accounting firm stores client tax records on a shared network folder. The owner wants to ensure that only the three staff members who prepare taxes can open those files, while other employees can still access the general office folder. Which security concept should the owner apply to the tax records folder?

⚠ Common exam trap

The trap here is assuming that any protective technology, such as encryption or antivirus, can restrict which users open a file, when only permissions such as ACLs perform that authorization function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access control lists (ACLs) that grant permissions only to the tax preparers group

The requirement is an authorization decision about who may read specific files on a shared server. ACLs attached to the tax folder let the owner grant permissions to a tax preparers group and deny everyone else, while leaving the general office folder open to all staff. Encryption, firewalls, and antivirus address different risks and cannot enforce per-user file access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Full disk encryption on each employee workstation

    Why it's wrong here

    Full disk encryption protects data if a device is lost or stolen; it does not restrict which logged-in employees can open a network folder. Since all employees already use working machines and the concern is who may view the tax files, encryption of local disks would not stop an unauthorized employee from browsing to the shared folder and opening the records.

  • ✗

    A firewall rule that blocks the file server's SMB port for non-tax staff

    Why it's wrong here

    A firewall filtering SMB traffic is a network-level control applied by address or port, not by individual user identity. Blocking the port for some employees would also break their access to the general office folder and is impractical to manage per person, so it does not meet the requirement of limiting just the tax records to three named staff.

  • ✓

    Access control lists (ACLs) that grant permissions only to the tax preparers group

    Why this is correct

    ACLs are the standard mechanism for assigning permissions to specific users or groups on file and folder resources. By granting access only to a tax preparers group, the owner enforces authorization so that other employees are denied access to the tax records while remaining able to reach the general office folder, which matches the scenario exactly.

  • ✗

    Antivirus software configured to scan the shared folder nightly

    Why it's wrong here

    Antivirus scanning detects and removes malicious code; it has no role in deciding which employees may read a document. Running nightly scans on the folder would not prevent an unauthorized employee from opening the tax records, so it fails to satisfy the owner's requirement for restricting access to a defined group of users.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.