SSCP Access Controls Practice Question
A security administrator is configuring a Linux server that hosts a shared project directory. The requirement is that new files created in the directory /projects/team must automatically inherit the group owner of the parent directory rather than the primary group of the user who created them. The administrator wants the setting to apply only to that directory. Which command should the administrator use?
⚠ Common exam trap
It's easy for candidates to confuse the sticky bit with the setgid bit, since both are special permission bits applied to directories but serve entirely different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chmod g+s /projects/team
The setgid bit on a directory is the standard Unix mechanism for ensuring that files and subdirectories created within it inherit the directory's group ownership. This is commonly used for shared project directories where collaboration among group members is required. Other options either alter permissions without affecting ownership, change only the directory's group, or set the sticky bit, which controls deletion rather than ownership inheritance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
chmod +t /projects/team
Why it's wrong here
The +t flag sets the sticky bit, which restricts deletion of files in a directory so that only the file owner, directory owner, or root can remove them. It has no effect on group ownership inheritance. While useful for shared directories to prevent users from deleting each other's files, it does not satisfy the stated requirement about automatic group ownership of newly created files.
- ✗
setfacl -d -m g:team:rwx /projects/team
Why it's wrong here
This sets a default ACL granting the team group read, write, and execute permissions on newly created files, but it does not change the group ownership of those files. The requirement is specifically about group ownership inheritance, not permission grants. A default ACL affects permissions, not the owning group, so it does not meet the stated need.
- ✗
chown :team /projects/team
Why it's wrong here
This command changes the group ownership of the directory itself to team, but it does not configure inheritance for files created inside it. New files would still be assigned the creator's primary group unless the setgid bit is also set. The requirement is about automatic inheritance, not merely changing the directory's group, so this command alone is insufficient.
- ✓
chmod g+s /projects/team
Why this is correct
Setting the setgid bit on a directory causes new files and subdirectories created within it to inherit the directory's group ownership instead of the creator's primary group. This directly satisfies the requirement that files in /projects/team retain the team group. The command applies only to the specified directory and does not affect other paths, which matches the scoped requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.