Courseiva

CCNA Windows Access Controls Questions

10 questions · Windows Access Controls topic · All types, answers revealed

1
MCQmedium

A security analyst is investigating a Windows Server 2019 file server where a user named Alice reports she cannot open a file in a shared folder even though she is a member of a group that has 'Modify' permission on that file. The analyst runs 'icacls' and sees that Alice's user account has an explicit 'Deny' entry for 'Read & execute' on the file. What is the most likely reason Alice cannot access the file?

A.Explicit Deny permissions take precedence over any Allow permissions, including those inherited from group membership.
B.The file's Share permissions are more restrictive than its NTFS permissions, preventing access.
C.Alice's group membership has not been refreshed in her current logon token, so the Modify permission is not applied.
D.The 'Modify' permission assigned to Alice's group is inherited from a parent folder and is therefore ignored.
AnswerA

In Windows ACL evaluation, an explicit Deny ACE is evaluated before any Allow ACE, regardless of whether the Allow comes from group membership or inheritance. Because Alice's user account has a direct Deny on 'Read & execute', that deny overrides the Modify permission granted to her group, preventing her from opening the file. This is a fundamental rule of Windows access control.

Why this answer

Windows evaluates explicit Deny ACEs before Allow ACEs, and this precedence applies even when the Allow comes from group membership. An explicit Deny on a user account directly blocks the permission, overriding any group-based Allow. The analyst's observation of the explicit Deny on Alice's account explains why she cannot open the file despite her group having Modify.

Exam trap

The trap here is assuming that group-based Allow permissions can override a direct Deny on a user account, when in fact explicit Deny always wins.

2
MCQhard

A security consultant is reviewing a Windows Server 2019 file server. The folder C:\Projects has a DACL that includes an entry for the group 'Contractors' with the following advanced permissions: 'List folder / read data', 'Read attributes', 'Read extended attributes', 'Read permissions', and 'Synchronize'. The consultant notices that a contractor user can open and read files in the folder but cannot create new files or modify existing ones. Which access control concept best explains this behavior?

A.The contractor user has the 'Modify' permission, but a Deny entry for 'Write' is present.
B.The contractor user is a member of the 'Users' group, which has the Read & execute permission by default.
C.The contractor user has been assigned the Read & execute basic permission, which includes the listed advanced permissions.
D.The contractor user has been assigned the Write basic permission, but inheritance is blocked on the folder.
AnswerC

The listed advanced permissions (List folder/read data, Read attributes, Read extended attributes, Read permissions, Synchronize) are exactly those that comprise the Read & execute basic permission (plus Read for files). This explains why the contractor can read but not write. The basic permission is a shorthand for this set of advanced permissions, and it is commonly used to grant read-only access to folders and files.

Why this answer

The advanced permissions listed are the components of the Read & execute basic permission. This permission allows reading and executing files but not writing or modifying them. The contractor's inability to create or modify files is directly explained by this permission set, which is commonly used for read-only access.

Exam trap

The trap here is assuming that any advanced permission entry must correspond to a custom set, overlooking that these specific advanced permissions are exactly the Read & execute basic permission.

3
MCQeasy

A junior administrator is setting up a shared folder on a Windows Server 2022 member server. The folder will be accessed by a group called 'SalesTeam'. The administrator wants to ensure that members of SalesTeam can read and write files, but cannot change permissions or take ownership. Which NTFS permission should the administrator assign to the SalesTeam group?

A.Write
B.Read & execute
C.Full Control
D.Modify
AnswerD

The Modify permission includes Read & execute, Write, and Delete, but does not include Change permissions or Take ownership. This allows SalesTeam members to read and write files without the ability to alter ACLs or ownership. It is the appropriate standard permission for collaborative file access where users need to edit content but not manage security.

Why this answer

The Modify permission provides the necessary read and write access without granting the ability to change permissions or take ownership. It is the standard choice for groups that need to collaborate on files. Full Control would be excessive, while Write and Read & execute each lack essential capabilities for the scenario.

Exam trap

The trap here is confusing the Modify permission with Full Control, forgetting that Modify excludes the ability to change permissions or take ownership.

4
MCQmedium

Which Windows feature allows for fine-grained access control based on user attributes like department or project code rather than just security groups?

A.Access-Based Enumeration (ABE)
B.Dynamic Access Control (DAC)
C.NTFS Permissions
D.User Account Control (UAC)
AnswerB

DAC uses claims-based identity and resource properties to enforce access. It allows for complex rules, such as 'only managers in the Finance department can access files marked as sensitive,' which is far more efficient than managing membership in dozens of static security groups across the domain.

Why this answer

Dynamic Access Control (DAC) allows administrators to create policies based on resource and user properties, providing a more flexible and scalable alternative to traditional security groups. This is essential in large organizations where maintaining thousands of security groups becomes unmanageable. DAC enhances the GSEC focus on least privilege by enabling context-aware access decisions that adapt automatically as user attributes change within Active Directory or file metadata.

Exam trap

Candidates often default to 'Group Policy' or 'Active Directory Groups' as the answer. They fail to distinguish between group-based access and the attribute-based flexibility offered by Dynamic Access Control.

5
MCQhard

Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?

A.Files and subfolders inherit the permissions from the parent.
B.Only existing files are modified.
C.The permissions are applied to C:\Data only, not children.
D.The user cannot delete the folder.
AnswerA

Object Inherit (OI) ensures files inherit the ACE, and Container Inherit (CI) ensures subfolders inherit the ACE. These flags are critical for administrative efficiency, as they automatically propagate security settings to all child objects, ensuring consistent application of the least privilege principle throughout the file hierarchy.

Why this answer

The (OI) flag stands for Object Inherit, and (CI) stands for Container Inherit. These flags ensure that permissions assigned to the parent folder propagate to all files and subfolders within the directory. This is essential for maintaining consistent access control in environments with deep directory structures.

Without these flags, newly created files or subfolders might not inherit the necessary security descriptors, leading to potential access gaps or security policy bypasses.

Exam trap

Candidates frequently confuse inheritance flags with explicit permission grants or deny rules, misinterpreting how permissions flow down directory trees.

6
MCQmedium

A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?

A.User Account Control (UAC)
B.BitLocker Drive Encryption
C.Share Permissions
D.Group Policy Object (GPO) Inheritance
AnswerC

Share permissions act as the first gatekeeper for network resources. If the Share permission is set to 'Deny' or does not include the user, they cannot access the contents regardless of their NTFS permissions. Both layers must permit access for the user to view or modify files.

Why this answer

Effective access in Windows is the intersection of NTFS permissions and Share permissions. If an account is denied access at the Share level, it will override any Read permissions granted via NTFS. Understanding this dual-layer architecture is critical for troubleshooting access issues, as security professionals must verify both file system attributes and network-level sharing configurations to ensure that policies are applied correctly and consistently across the environment.

Exam trap

Candidates often focus solely on NTFS permissions and assume that if they are correct, access is granted. They forget that Share permissions are a separate layer that can block access entirely.

7
MCQmedium

A security analyst is reviewing file server permissions and notices that a user, Elena, has the 'Modify' permission on a folder via group membership in 'Project_X', but she is also a member of the 'Contractors' group, which has an explicit 'Deny' for 'Write'. Elena reports she cannot edit any files in the folder. What is the most likely explanation for this behavior?

A.The 'Deny' permission only applies if Elena is directly listed, not via group membership.
B.The 'Write' permission is not included in the 'Modify' permission, so the Deny for Write does not affect Modify.
C.The 'Deny' permission for the 'Contractors' group takes precedence over the 'Allow' permission inherited from 'Project_X'.
D.The 'Modify' permission from 'Project_X' is inherited and therefore is overridden by the explicit 'Deny'.
AnswerC

In Windows access control, explicit Deny entries in an ACL override any Allow permissions, whether inherited or explicit. Because Elena is a member of 'Contractors', the Deny for Write applies directly to her, blocking the Modify permission from 'Project_X'. This is by design to ensure security restrictions are enforced.

Why this answer

Windows access control evaluates Deny entries before Allow entries. An explicit Deny for a group applies to all its members, and it overrides any Allow permissions, even those granted through other group memberships or inheritance. Thus, Elena's Write access is blocked by the Deny on the Contractors group, despite her Modify permission from Project_X.

Exam trap

The trap here is assuming that the most permissive permission wins or that group membership does not trigger Deny entries.

8
MCQhard

A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?

A.The 'Sales' group has an explicit 'Deny' for 'Delete' that overrides the 'Full Control' from 'Managers'.
B.The 'Full Control' permission from 'Managers' does not include the 'Delete' permission.
C.Bob's user account has an explicit 'Deny' for 'Delete' that is inherited from the parent folder.
D.The 'Read & Execute' permission from 'Sales' is more restrictive and overrides the 'Full Control' from 'Managers'.
AnswerA

If the Sales group has an explicit Deny for Delete, that Deny takes precedence over the Allow from Managers. Even though Bob is a Manager with Full Control, the Deny from Sales membership blocks deletion. This is a classic case of Deny overriding Allow, and it explains why Bob cannot delete files despite having Full Control via another group.

Why this answer

In Windows ACLs, an explicit Deny entry overrides any Allow permissions, regardless of the source. If the Sales group has a Deny for Delete, Bob's membership in that group triggers the Deny, preventing deletion even though Managers grants Full Control. This is the most plausible explanation given the information.

Exam trap

The trap here is assuming that having Full Control from one group guarantees all actions, ignoring possible Deny entries from other group memberships.

9
MCQhard

An administrator is configuring NTFS permissions on a folder named C:\Audit. The folder currently has inheritance enabled from C:\, which grants Users Read & Execute. The administrator wants to prevent members of the group Temp_Contractors from accessing the folder, but they must still be able to access other folders on the C: drive. The administrator adds an explicit Deny Full Control permission for Temp_Contractors on C:\Audit. What is the effect of this change?

A.Members of Temp_Contractors will be denied access to the entire C: drive because Deny permissions propagate upward.
B.The Deny permission will be ignored because inherited Allow permissions take precedence over explicit Deny permissions.
C.Members of Temp_Contractors will be denied access to C:\Audit, but will retain their inherited permissions on other folders.
D.Members of Temp_Contractors will still have access to C:\Audit because they are also members of the Users group, which has inherited Allow permissions.
AnswerC

An explicit Deny permission on C:\Audit overrides any inherited Allow permissions for that folder and its subfolders. Since the Deny is applied only to C:\Audit, it does not affect other folders on the C: drive. Thus, Temp_Contractors are denied access to C:\Audit but retain access elsewhere as per inherited permissions.

Why this answer

Explicit Deny permissions override inherited Allow permissions. Placing a Deny Full Control for Temp_Contractors on C:\Audit blocks their access to that folder and its subfolders (if inheritance is enabled), but does not affect other folders on the C: drive. Therefore, the correct outcome is that Temp_Contractors are denied access to C:\Audit while retaining access to other folders.

Exam trap

The trap here is thinking that Deny permissions propagate upward or that inherited Allow can override an explicit Deny. In reality, explicit Deny takes precedence and applies only to the object and its children.

10
MCQeasy

A security administrator is reviewing the access control model used by a Windows Server 2022 domain controller. They need to ensure that when a user logs on, the system evaluates the user's group memberships and generates a data structure that is used for all subsequent access checks. Which component is responsible for this?

A.Group Policy Object (GPO)
B.Security Descriptor
C.Access Token
D.Security Identifier (SID)
AnswerC

The access token is created during logon and contains the user's SID, group SIDs, and privileges. It is attached to every process or thread the user runs and is used by the Security Reference Monitor to perform access checks against objects' security descriptors. Thus, it is the data structure that holds the security context for access evaluation.

Why this answer

During interactive or network logon, the Local Security Authority (LSA) authenticates the user and creates an access token. This token includes the user's SID, the SIDs of all groups the user belongs to, and any privileges assigned. The token is then used by the Security Reference Monitor for all access checks against securable objects.

Therefore, the access token is the correct component.

Exam trap

The trap here is confusing the access token with the Security Descriptor, which is attached to objects, not users, and is used during access checks but is not generated at logon.

Ready to test yourself?

Try a timed practice session using only Windows Access Controls questions.