Courseiva
Windows Access Controls →mediumMultiple Choice

GSEC Windows Access Controls Practice Question

A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?

⚠ Common exam trap

Candidates often focus solely on NTFS permissions and assume that if they are correct, access is granted. They forget that Share permissions are a separate layer that can block access entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Share Permissions

Effective access in Windows is the intersection of NTFS permissions and Share permissions. If an account is denied access at the Share level, it will override any Read permissions granted via NTFS. Understanding this dual-layer architecture is critical for troubleshooting access issues, as security professionals must verify both file system attributes and network-level sharing configurations to ensure that policies are applied correctly and consistently across the environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User Account Control (UAC)

    Why it's wrong here

    UAC primarily manages administrative elevation prompts and integrity levels for applications. It does not control low-level file system access permissions for standard users, nor does it impact the intersection between NTFS and Share permissions during remote or local folder access requests for standard data files.

  • ✗

    BitLocker Drive Encryption

    Why it's wrong here

    BitLocker provides full-volume encryption to protect data at rest against physical theft. It operates at the storage layer and does not perform access control checks based on user identity once the volume is unlocked and the operating system has successfully mounted the file system.

  • ✓

    Share Permissions

    Why this is correct

    Share permissions act as the first gatekeeper for network resources. If the Share permission is set to 'Deny' or does not include the user, they cannot access the contents regardless of their NTFS permissions. Both layers must permit access for the user to view or modify files.

  • ✗

    Group Policy Object (GPO) Inheritance

    Why it's wrong here

    GPO inheritance dictates configuration settings and registry keys pushed from a domain controller. While GPOs can restrict software execution or modify user rights, they do not directly evaluate or override individual folder-level access control entries during standard file system navigation operations.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.