GSEC Windows Access Controls Practice Question
A security consultant is reviewing a Windows Server 2019 file server. The folder C:\Projects has a DACL that includes an entry for the group 'Contractors' with the following advanced permissions: 'List folder / read data', 'Read attributes', 'Read extended attributes', 'Read permissions', and 'Synchronize'. The consultant notices that a contractor user can open and read files in the folder but cannot create new files or modify existing ones. Which access control concept best explains this behavior?
⚠ Common exam trap
The trap here is assuming that any advanced permission entry must correspond to a custom set, overlooking that these specific advanced permissions are exactly the Read & execute basic permission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The contractor user has been assigned the Read & execute basic permission, which includes the listed advanced permissions.
The advanced permissions listed are the components of the Read & execute basic permission. This permission allows reading and executing files but not writing or modifying them. The contractor's inability to create or modify files is directly explained by this permission set, which is commonly used for read-only access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The contractor user has the 'Modify' permission, but a Deny entry for 'Write' is present.
Why it's wrong here
If Modify were assigned, the user would have Write unless a Deny for Write existed. However, the scenario does not mention any Deny entries, and the listed advanced permissions are all read-related. The absence of Write-related permissions in the DACL entry is sufficient to prevent writing. A Deny would be an additional layer, but it is not indicated here.
- ✗
The contractor user is a member of the 'Users' group, which has the Read & execute permission by default.
Why it's wrong here
While the Users group often has Read & execute on many system folders, the scenario describes a specific DACL entry for the Contractors group with advanced permissions. The behavior is directly explained by that entry, not by default group membership. The question asks for the concept that best explains the behavior, which is the specific permission set assigned to the group.
- ✓
The contractor user has been assigned the Read & execute basic permission, which includes the listed advanced permissions.
Why this is correct
The listed advanced permissions (List folder/read data, Read attributes, Read extended attributes, Read permissions, Synchronize) are exactly those that comprise the Read & execute basic permission (plus Read for files). This explains why the contractor can read but not write. The basic permission is a shorthand for this set of advanced permissions, and it is commonly used to grant read-only access to folders and files.
- ✗
The contractor user has been assigned the Write basic permission, but inheritance is blocked on the folder.
Why it's wrong here
The Write permission would allow creating files and modifying data. The contractor cannot do these things, so Write is not assigned. Blocking inheritance would not remove Write permissions if they were explicitly assigned; it would only prevent inheritance from parent folders. The observed behavior is consistent with Read & execute, not Write.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.