220-1102 exam dumps

220-1102 practice question 168 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 168

Single answerFile servers

A small office uses a Windows file server to store department documents on a shared folder named \FS1\Departments. Users report that they can open files in the share, but they cannot save changes or create new files. The technician verifies that the users are members of the correct Active Directory security group. On the shared folder, the Share permission for that group is set to Read, and the NTFS permission is set to Modify. What should the technician do to restore the users' ability to save files while still keeping permissions appropriately limited?

  1. A

    Change the Share permission for the group from Read to Change

  2. B

    Change the NTFS permission for the group from Modify to Full Control

  3. C

    Add the users to the local Administrators group on the file server

  4. D

    Remove the NTFS permissions and manage access using only Share permissions

Show answer and explanation

Correct answer: A

Explanation

On Windows file servers, both Share permissions and NTFS permissions apply to network access, and the effective permission is the most restrictive result between the two. In this scenario, Share is set to Read, which blocks saving and file creation even though NTFS is set to Modify. The appropriate fix is to change the Share permission to Change so users can write to the share without granting unnecessary Full Control. This aligns with Microsoft best practices for shared folders: use least privilege, avoid overassigning administrative rights, and understand that Share and NTFS permissions work together for SMB-based file access.

  • A. Correct.

    Correct. Effective access to a Windows file share is determined by the most restrictive combination of Share and NTFS permissions. Even though NTFS is set to Modify, Share is limited to Read, so users can open files but cannot save changes or create new ones over the network. Changing the Share permission to Change allows write access while still avoiding unnecessary Full Control.

  • B. Incorrect.

    Incorrect. NTFS Modify already provides the ability to read, write, and delete files as needed for normal collaboration. Raising NTFS to Full Control is excessive and grants additional rights, such as changing permissions, that are not required to solve the problem.

  • C. Incorrect.

    Incorrect. Adding standard users to the local Administrators group violates least-privilege best practices and creates a major security risk. It would also provide far more access than needed for users who only need to update files in a department share.

  • D. Incorrect.

    Incorrect. While some environments simplify administration by setting Share permissions broadly and controlling access mainly with NTFS, removing NTFS permissions is not the correct fix here. NTFS permissions are important for securing local and network access, and the immediate issue is the restrictive Share permission.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam