EX200 Manage users and groups Practice Question
Exhibit
Refer to the exhibit. [exhibit] getfacl /shared # file: shared # owner: root # group: staff user::rwx user:jdoe:--- group::rwx mask::rwx other::--- [/exhibit]
A user jdoe, who is a member of the group staff, reports they cannot access the directory /shared. The administrator runs getfacl /shared and receives the output shown. Which of the following explains the issue?
⚠ Common exam trap
The trap here is that candidates often focus on group permissions or the mask, overlooking that a user-specific ACL entry with no permissions explicitly denies access, overriding all other entries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An ACL entry denies all permissions for jdoe
The getfacl output shows a user ACL entry for jdoe with permissions '---' (no read, write, or execute), which explicitly denies all access. This user-specific ACL entry overrides any group or other permissions, so jdoe cannot access /shared regardless of group staff membership.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The group staff does not have execute permission
Why it's wrong here
The group ACL entry for staff is explicitly rwx, so the owning group has read, write, and execute permission. Because the group class is not missing execute, the inability to access the directory cannot be blamed on the group's lack of execute. The actual cause is a more specific user ACL entry that applies before group permissions are considered.
- ✓
An ACL entry denies all permissions for jdoe
Why this is correct
Access control list evaluation checks a named user entry for jdoe before it checks the owning group. The entry user:jdoe:--- supplies no read, write, or execute bits, which causes every attempted operation on the directory to fail for jdoe. This explicit deny overrides the otherwise permissive group::rwx entry that staff members would normally inherit.
- ✗
The mask entry restricts group permissions
Why it's wrong here
The mask is set to rwx, meaning it places no ceiling on the permissions granted to named users, named groups, or the owning group. A mask of rwx would not reduce the group::rwx entry to a lower effective permission set. The denial jdoe experiences is generated by the named user entry, not by any mask-imposed restriction on the group class.
- ✗
The directory is read-only for the owner
Why it's wrong here
The owner ACL entry on the directory is rwx, giving the directory owner full control, but that entry has no bearing on jdoe because jdoe is not the directory owner. During access evaluation, the owner entry is only consulted when the requesting UID matches the directory's owner UID. Since jdoe is a member of staff, his access is determined by the named user entry, which is what actually denies him.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.