Courseiva

GSEC · topic practice

Windows Access Controls practice questions

This domain covers Windows access control mechanisms: NTFS permissions, share permissions, Active Directory security groups, and access tokens. You must analyze effective permissions, inheritance, and explicit denies. Questions present scenarios about users in multiple groups, requiring you to determine resulting access or configure permissions to meet a requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Windows Access Controls

What the exam tests

What to know about Windows Access Controls

Be able to calculate effective permissions for a user given NTFS and share permissions, group memberships, and inheritance settings. The most important thing: explicit deny always wins, and effective access is the intersection of share and NTFS permissions.

NTFS permissions and inheritance, including explicit deny and disabling inheritance.

Access token generation during logon, containing user SID and group SIDs.

Effective permissions calculation when a user belongs to multiple groups.

Share permissions vs NTFS permissions and how they combine for network access.

Watch out for

Common Windows Access Controls exam traps

  • ▸Forgetting that explicit deny overrides all allow permissions, even if the user is in a group that allows access.
  • ▸Assuming share permissions are evaluated the same as NTFS; they combine to give the most restrictive effective access.
  • ▸Overlooking that disabling inheritance can convert inherited permissions to explicit or remove them entirely.

Practice set

Windows Access Controls questions

20 questions · select your answer, then reveal the explanation

An administrator needs to configure a local Windows security policy so that standard users cannot install unauthorized software, even if they have local administrator rights on non-domain joined workstations. Which User Account Control (UAC) policy setting enforces administrator approval for all applications requiring elevation?

A file server has 'Everyone: Read' NTFS permissions and 'Administrators: Full Control' Share permissions. A domain user tries to access a file over the network. What is the result?

Question 3mediummultiple choice
Study the full ACL explanation →

When configuring Windows Access Control Lists (ACLs), which TWO of the following statements correctly describe the behavior of 'Explicit' versus 'Inherited' permissions?

You are auditing a server and find that a user has 'Full Control' on a file despite not being in the explicit access list. What is the most likely reason?

Question 5hardmultiple choice
Study the full ACL explanation →

Which THREE of the following are true regarding the behavior of 'Deny' permissions in Windows Access Control Lists?

A Windows file server hosts a shared folder named Projects on an NTFS volume. The Share permissions for Projects are set to Everyone: Change. The NTFS permissions on the folder grant the domain group Project_Managers Modify and the domain group Project_Staff Read & Execute. A user, Maria, is a member of both Project_Managers and Project_Staff. She attempts to delete a file within the Projects folder but receives an 'Access Denied' error. What is the most likely cause?

A security administrator is configuring a Windows Server 2022 file share. The share permissions are set to 'Everyone: Read'. The NTFS permissions on the folder are set to 'SalesGroup: Modify'. A user named Bob is a member of SalesGroup. He attempts to save a new file to the share. What will happen?

A security analyst is examining a Windows 10 workstation and notices that a user account named 'BackupSvc' has the 'Back up files and directories' user right assigned. The analyst wants to understand the implications of this right. Which statement accurately describes a capability granted by this user right?

A security analyst is examining the access control settings on a Windows Server 2019 file server. The analyst observes that a folder has inheritance enabled, and a user named Carol has Full Control permissions on the folder. Carol is also a member of a group that has 'Deny' for 'Write' on a subfolder. Which two statements correctly describe the effective permissions for Carol on the subfolder? (Choose two.)

A security analyst is reviewing access on a Windows Server 2022 file server. A folder named C:\Finance has an explicit ACE granting the user Alice Modify permission. Alice is also a member of the group Finance_Readers, which has an explicit Deny Write ACE on the same folder. Alice attempts to write a file to C:\Finance. What is the result and why?

A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?

Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?

Exhibit

icacls C:\Data /grant 'Finance_Users:(OI)(CI)M'

Which Windows feature allows for fine-grained access control based on user attributes like department or project code rather than just security groups?

A security analyst is reviewing file server permissions and notices that a user, Elena, has the 'Modify' permission on a folder via group membership in 'Project_X', but she is also a member of the 'Contractors' group, which has an explicit 'Deny' for 'Write'. Elena reports she cannot edit any files in the folder. What is the most likely explanation for this behavior?

A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?

A security analyst is investigating a Windows Server 2019 file server where a user named Alice reports she cannot open a file in a shared folder even though she is a member of a group that has 'Modify' permission on that file. The analyst runs 'icacls' and sees that Alice's user account has an explicit 'Deny' entry for 'Read & execute' on the file. What is the most likely reason Alice cannot access the file?

A junior administrator is setting up a shared folder on a Windows Server 2022 member server. The folder will be accessed by a group called 'SalesTeam'. The administrator wants to ensure that members of SalesTeam can read and write files, but cannot change permissions or take ownership. Which NTFS permission should the administrator assign to the SalesTeam group?

A security consultant is reviewing a Windows Server 2019 file server. The folder C:\Projects has a DACL that includes an entry for the group 'Contractors' with the following advanced permissions: 'List folder / read data', 'Read attributes', 'Read extended attributes', 'Read permissions', and 'Synchronize'. The consultant notices that a contractor user can open and read files in the folder but cannot create new files or modify existing ones. Which access control concept best explains this behavior?

A security administrator is reviewing the access control model used by a Windows Server 2022 domain controller. They need to ensure that when a user logs on, the system evaluates the user's group memberships and generates a data structure that is used for all subsequent access checks. Which component is responsible for this?

An administrator is configuring NTFS permissions on a folder named C:\Audit. The folder currently has inheritance enabled from C:\, which grants Users Read & Execute. The administrator wants to prevent members of the group Temp_Contractors from accessing the folder, but they must still be able to access other folders on the C: drive. The administrator adds an explicit Deny Full Control permission for Temp_Contractors on C:\Audit. What is the effect of this change?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Windows Access Controls sessions

Start a Windows Access Controls only practice session

Every question in these sessions is drawn from the Windows Access Controls domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Windows Access Controls?
Be able to calculate effective permissions for a user given NTFS and share permissions, group memberships, and inheritance settings. The most important thing: explicit deny always wins, and effective access is the intersection of share and NTFS permissions.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Windows Access Controls questions in a focused session?
Yes — the session launcher on this page draws every question from the Windows Access Controls domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.