GSEC Windows Access Controls Practice Question
A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?
⚠ Common exam trap
Candidates often focus solely on NTFS permissions and assume that if they are correct, access is granted. They forget that Share permissions are a separate layer that can block access entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Share Permissions
Effective access in Windows is the intersection of NTFS permissions and Share permissions. If an account is denied access at the Share level, it will override any Read permissions granted via NTFS. Understanding this dual-layer architecture is critical for troubleshooting access issues, as security professionals must verify both file system attributes and network-level sharing configurations to ensure that policies are applied correctly and consistently across the environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User Account Control (UAC)
Why it's wrong here
UAC primarily manages administrative elevation prompts and integrity levels for applications. It does not control low-level file system access permissions for standard users, nor does it impact the intersection between NTFS and Share permissions during remote or local folder access requests for standard data files.
- ✗
BitLocker Drive Encryption
Why it's wrong here
BitLocker provides full-volume encryption to protect data at rest against physical theft. It operates at the storage layer and does not perform access control checks based on user identity once the volume is unlocked and the operating system has successfully mounted the file system.
- ✓
Share Permissions
Why this is correct
Share permissions act as the first gatekeeper for network resources. If the Share permission is set to 'Deny' or does not include the user, they cannot access the contents regardless of their NTFS permissions. Both layers must permit access for the user to view or modify files.
- ✗
Group Policy Object (GPO) Inheritance
Why it's wrong here
GPO inheritance dictates configuration settings and registry keys pushed from a domain controller. While GPOs can restrict software execution or modify user rights, they do not directly evaluate or override individual folder-level access control entries during standard file system navigation operations.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.