GSEC · domain
Windows Access Controls
This domain covers Windows access control mechanisms: NTFS permissions, share permissions, Active Directory security groups, and access tokens. You must analyze effective permissions, inheritance, and explicit denies. Questions present scenarios about users in multiple groups, requiring you to determine resulting access or configure permissions to meet a requirement.
Focused practice
Practice Windows Access Controls questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Windows Access Controls
Be able to calculate effective permissions for a user given NTFS and share permissions, group memberships, and inheritance settings. The most important thing: explicit deny always wins, and effective access is the intersection of share and NTFS permissions.
NTFS permissions and inheritance, including explicit deny and disabling inheritance.
Access token generation during logon, containing user SID and group SIDs.
Effective permissions calculation when a user belongs to multiple groups.
Share permissions vs NTFS permissions and how they combine for network access.
Watch out for
Common Windows Access Controls exam traps
- ▸Forgetting that explicit deny overrides all allow permissions, even if the user is in a group that allows access.
- ▸Assuming share permissions are evaluated the same as NTFS; they combine to give the most restrictive effective access.
- ▸Overlooking that disabling inheritance can convert inherited permissions to explicit or remove them entirely.
Question index
All Windows Access Controls questions (10)
Click any question to see the full explanation, or start a practice session above.
A security analyst is investigating a Windows Server 2019 file server where a user named Alice reports she cannot open a file in a shared folder even though she is a member of a group that has 'Modify' permission on that file. The analyst runs 'icacls' and sees that Alice's user account has an explicit 'Deny' entry for 'Read & execute' on the file. What is the most likely reason Alice cannot access the file?
Medium2A security consultant is reviewing a Windows Server 2019 file server. The folder C:\Projects has a DACL that includes an entry for the group 'Contractors' with the following advanced permissions: 'List folder / read data', 'Read attributes', 'Read extended attributes', 'Read permissions', and 'Synchronize'. The consultant notices that a contractor user can open and read files in the folder but cannot create new files or modify existing ones. Which access control concept best explains this behavior?
Hard3A junior administrator is setting up a shared folder on a Windows Server 2022 member server. The folder will be accessed by a group called 'SalesTeam'. The administrator wants to ensure that members of SalesTeam can read and write files, but cannot change permissions or take ownership. Which NTFS permission should the administrator assign to the SalesTeam group?
Easy4Which Windows feature allows for fine-grained access control based on user attributes like department or project code rather than just security groups?
Medium5Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?
Hard6A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?
Medium7A security analyst is reviewing file server permissions and notices that a user, Elena, has the 'Modify' permission on a folder via group membership in 'Project_X', but she is also a member of the 'Contractors' group, which has an explicit 'Deny' for 'Write'. Elena reports she cannot edit any files in the folder. What is the most likely explanation for this behavior?
Medium8A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?
Hard9An administrator is configuring NTFS permissions on a folder named C:\Audit. The folder currently has inheritance enabled from C:\, which grants Users Read & Execute. The administrator wants to prevent members of the group Temp_Contractors from accessing the folder, but they must still be able to access other folders on the C: drive. The administrator adds an explicit Deny Full Control permission for Temp_Contractors on C:\Audit. What is the effect of this change?
Hard10A security administrator is reviewing the access control model used by a Windows Server 2022 domain controller. They need to ensure that when a user logs on, the system evaluates the user's group memberships and generates a data structure that is used for all subsequent access checks. Which component is responsible for this?
EasyOther domains
All GSEC exam domains
Frequently asked questions
- What does the Windows Access Controls domain cover on the GSEC exam?
- Be able to calculate effective permissions for a user given NTFS and share permissions, group memberships, and inheritance settings. The most important thing: explicit deny always wins, and effective access is the intersection of share and NTFS permissions.
- How many questions are in this domain?
- This page lists all 10 Windows Access Controls questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Windows Access Controls questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.