GSEC Windows Access Controls Practice Question
Exhibit
icacls C:\Data /grant 'Finance_Users:(OI)(CI)M'
Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?
⚠ Common exam trap
Candidates frequently confuse inheritance flags with explicit permission grants or deny rules, misinterpreting how permissions flow down directory trees.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Files and subfolders inherit the permissions from the parent.
The (OI) flag stands for Object Inherit, and (CI) stands for Container Inherit. These flags ensure that permissions assigned to the parent folder propagate to all files and subfolders within the directory. This is essential for maintaining consistent access control in environments with deep directory structures. Without these flags, newly created files or subfolders might not inherit the necessary security descriptors, leading to potential access gaps or security policy bypasses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Files and subfolders inherit the permissions from the parent.
Why this is correct
Object Inherit (OI) ensures files inherit the ACE, and Container Inherit (CI) ensures subfolders inherit the ACE. These flags are critical for administrative efficiency, as they automatically propagate security settings to all child objects, ensuring consistent application of the least privilege principle throughout the file hierarchy.
- ✗
Only existing files are modified.
Why it's wrong here
These flags apply to both existing and future objects created within the container. If it only applied to existing objects, administrators would need to manually re-run the command every time a new file was added, creating significant management overhead and increasing the risk of security misconfiguration.
- ✗
The permissions are applied to C:\Data only, not children.
Why it's wrong here
The flags specifically instruct Windows to propagate the Access Control Entry to child objects. If the flags were omitted, the permissions would be applied only to the C:\Data folder itself, leaving the contents vulnerable or inaccessible depending on the existing inherited or explicit permission settings.
- ✗
The user cannot delete the folder.
Why it's wrong here
The (M) flag stands for Modify, which includes the ability to read, write, and delete files. These flags do not restrict deletion; rather, they define the scope of inheritance. The deletion capability is a function of the modify permission itself, not the inheritance flags applied to the ACL.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.