Courseiva
Windows Access Controls →mediumMultiple Choice

GSEC Windows Access Controls Practice Question

A security analyst is investigating a Windows Server 2019 file server where a user named Alice reports she cannot open a file in a shared folder even though she is a member of a group that has 'Modify' permission on that file. The analyst runs 'icacls' and sees that Alice's user account has an explicit 'Deny' entry for 'Read & execute' on the file. What is the most likely reason Alice cannot access the file?

⚠ Common exam trap

The trap here is assuming that group-based Allow permissions can override a direct Deny on a user account, when in fact explicit Deny always wins.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Explicit Deny permissions take precedence over any Allow permissions, including those inherited from group membership.

Windows evaluates explicit Deny ACEs before Allow ACEs, and this precedence applies even when the Allow comes from group membership. An explicit Deny on a user account directly blocks the permission, overriding any group-based Allow. The analyst's observation of the explicit Deny on Alice's account explains why she cannot open the file despite her group having Modify.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Explicit Deny permissions take precedence over any Allow permissions, including those inherited from group membership.

    Why this is correct

    In Windows ACL evaluation, an explicit Deny ACE is evaluated before any Allow ACE, regardless of whether the Allow comes from group membership or inheritance. Because Alice's user account has a direct Deny on 'Read & execute', that deny overrides the Modify permission granted to her group, preventing her from opening the file. This is a fundamental rule of Windows access control.

  • ✗

    The file's Share permissions are more restrictive than its NTFS permissions, preventing access.

    Why it's wrong here

    The question focuses on NTFS permissions (icacls shows NTFS ACLs). Share permissions are separate and would not be visible via icacls. While share permissions can restrict access, the explicit Deny on the NTFS ACL is sufficient to block access. The scenario does not indicate share-level restrictions.

  • ✗

    Alice's group membership has not been refreshed in her current logon token, so the Modify permission is not applied.

    Why it's wrong here

    While group membership changes require a new logon to update the token, the scenario states Alice is a member of the group and the analyst sees the group has Modify permission. The explicit Deny on her account is a more direct and definitive cause. Token refresh issues would affect all group-based access, not specifically a file with an explicit Deny.

  • ✗

    The 'Modify' permission assigned to Alice's group is inherited from a parent folder and is therefore ignored.

    Why it's wrong here

    Inherited permissions are not ignored; they are effective unless blocked or overridden by an explicit Deny. In this scenario, the group's Modify permission could be inherited or explicit, but the presence of an explicit Deny on Alice's account is what blocks access. Inheritance alone does not cause permissions to be disregarded.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.