GSEC Windows Access Controls Practice Question
An administrator is configuring NTFS permissions on a folder named C:\Audit. The folder currently has inheritance enabled from C:\, which grants Users Read & Execute. The administrator wants to prevent members of the group Temp_Contractors from accessing the folder, but they must still be able to access other folders on the C: drive. The administrator adds an explicit Deny Full Control permission for Temp_Contractors on C:\Audit. What is the effect of this change?
⚠ Common exam trap
The trap here is thinking that Deny permissions propagate upward or that inherited Allow can override an explicit Deny. In reality, explicit Deny takes precedence and applies only to the object and its children.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Members of Temp_Contractors will be denied access to C:\Audit, but will retain their inherited permissions on other folders.
Explicit Deny permissions override inherited Allow permissions. Placing a Deny Full Control for Temp_Contractors on C:\Audit blocks their access to that folder and its subfolders (if inheritance is enabled), but does not affect other folders on the C: drive. Therefore, the correct outcome is that Temp_Contractors are denied access to C:\Audit while retaining access to other folders.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Members of Temp_Contractors will be denied access to the entire C: drive because Deny permissions propagate upward.
Why it's wrong here
Deny permissions do not propagate upward to parent folders. They apply only to the object where they are set and can be inherited by child objects if inheritance is enabled. Since the Deny is set on C:\Audit, it does not affect the parent C:\ or other folders. Therefore, access to the rest of the C: drive remains unchanged.
- ✗
The Deny permission will be ignored because inherited Allow permissions take precedence over explicit Deny permissions.
Why it's wrong here
In Windows access control, explicit Deny permissions take precedence over inherited Allow permissions. When evaluating access, the system checks for any Deny entries that match the user's SIDs; if found, access is denied regardless of Allow entries. Therefore, the explicit Deny on C:\Audit will override the inherited Allow from C:\.
- ✓
Members of Temp_Contractors will be denied access to C:\Audit, but will retain their inherited permissions on other folders.
Why this is correct
An explicit Deny permission on C:\Audit overrides any inherited Allow permissions for that folder and its subfolders. Since the Deny is applied only to C:\Audit, it does not affect other folders on the C: drive. Thus, Temp_Contractors are denied access to C:\Audit but retain access elsewhere as per inherited permissions.
- ✗
Members of Temp_Contractors will still have access to C:\Audit because they are also members of the Users group, which has inherited Allow permissions.
Why it's wrong here
Even if a user is a member of a group with Allow permissions, an explicit Deny for any group the user belongs to will override those Allows. The presence of the Users group with Allow does not negate the Deny for Temp_Contractors. The access check will find the Deny and reject access, so they will not have access.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.