Courseiva
Windows Access Controls →mediumMultiple Choice

GSEC Windows Access Controls Practice Question

A security analyst is reviewing file server permissions and notices that a user, Elena, has the 'Modify' permission on a folder via group membership in 'Project_X', but she is also a member of the 'Contractors' group, which has an explicit 'Deny' for 'Write'. Elena reports she cannot edit any files in the folder. What is the most likely explanation for this behavior?

⚠ Common exam trap

The trap here is assuming that the most permissive permission wins or that group membership does not trigger Deny entries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'Deny' permission for the 'Contractors' group takes precedence over the 'Allow' permission inherited from 'Project_X'.

Windows access control evaluates Deny entries before Allow entries. An explicit Deny for a group applies to all its members, and it overrides any Allow permissions, even those granted through other group memberships or inheritance. Thus, Elena's Write access is blocked by the Deny on the Contractors group, despite her Modify permission from Project_X.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'Deny' permission only applies if Elena is directly listed, not via group membership.

    Why it's wrong here

    Windows evaluates group memberships for both Allow and Deny permissions. An explicit Deny applied to a group affects all members of that group. Therefore, Elena's membership in 'Contractors' triggers the Deny. The statement is false; group-based Deny is effective and common in access control.

  • ✗

    The 'Write' permission is not included in the 'Modify' permission, so the Deny for Write does not affect Modify.

    Why it's wrong here

    The 'Modify' permission includes Write (and Read & Execute, among others). Therefore, a Deny on Write directly conflicts with the Write component of Modify. The Deny will block the Write capability, effectively preventing modification. This option misstates the composition of the Modify permission.

  • ✓

    The 'Deny' permission for the 'Contractors' group takes precedence over the 'Allow' permission inherited from 'Project_X'.

    Why this is correct

    In Windows access control, explicit Deny entries in an ACL override any Allow permissions, whether inherited or explicit. Because Elena is a member of 'Contractors', the Deny for Write applies directly to her, blocking the Modify permission from 'Project_X'. This is by design to ensure security restrictions are enforced.

  • ✗

    The 'Modify' permission from 'Project_X' is inherited and therefore is overridden by the explicit 'Deny'.

    Why it's wrong here

    While it is true that the Deny overrides, this option incorrectly states that the Modify permission is inherited. The scenario does not specify inheritance; it says Elena has Modify via group membership. Even if inherited, inheritance alone does not cause it to be overridden; it's the Deny precedence that matters. The key issue is Deny > Allow.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.