Courseiva
Windows Access Controls →hardMultiple Choice

GSEC Windows Access Controls Practice Question

A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that having Full Control from one group guarantees all actions, ignoring possible Deny entries from other group memberships.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'Sales' group has an explicit 'Deny' for 'Delete' that overrides the 'Full Control' from 'Managers'.

In Windows ACLs, an explicit Deny entry overrides any Allow permissions, regardless of the source. If the Sales group has a Deny for Delete, Bob's membership in that group triggers the Deny, preventing deletion even though Managers grants Full Control. This is the most plausible explanation given the information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The 'Sales' group has an explicit 'Deny' for 'Delete' that overrides the 'Full Control' from 'Managers'.

    Why this is correct

    If the Sales group has an explicit Deny for Delete, that Deny takes precedence over the Allow from Managers. Even though Bob is a Manager with Full Control, the Deny from Sales membership blocks deletion. This is a classic case of Deny overriding Allow, and it explains why Bob cannot delete files despite having Full Control via another group.

  • ✗

    The 'Full Control' permission from 'Managers' does not include the 'Delete' permission.

    Why it's wrong here

    Full Control includes all permissions, including Delete. Therefore, this statement is incorrect. If Bob truly had Full Control without any Deny, he would be able to delete files. The issue must be due to a conflicting Deny or another restriction. This option misrepresents the scope of Full Control.

  • ✗

    Bob's user account has an explicit 'Deny' for 'Delete' that is inherited from the parent folder.

    Why it's wrong here

    While an explicit Deny for Bob would indeed block deletion, the scenario does not indicate that Bob's account has such a Deny. It only mentions group memberships. The most likely cause is a Deny on one of the groups, not on Bob directly. This option introduces an unsupported assumption.

  • ✗

    The 'Read & Execute' permission from 'Sales' is more restrictive and overrides the 'Full Control' from 'Managers'.

    Why it's wrong here

    Windows permissions are additive: a user receives the union of all Allow permissions from all groups, unless a Deny is present. Read & Execute does not override Full Control; instead, the user would have Full Control if no Deny exists. This option incorrectly suggests that a less permissive Allow can override a more permissive Allow.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.