SY0-701 exam dumps

SY0-701 practice question 129 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 129

Single answerAccess control: Access control list (ACL) , Permissions

A systems administrator is reviewing access to a shared finance folder on a Windows file server after an employee transferred from Accounting to Marketing. The employee should no longer be able to open or modify files in the folder, but an audit shows the user can still access it when logging in normally. The folder's NTFS permissions grant access only to the Finance group. The administrator discovers the user was removed from the Finance group, but the user is still a member of a legacy group called All_Dept_Share that has Read access to the same folder through the ACL. Which action best resolves the issue while following least privilege principles?

  1. A

    Remove the user from the All_Dept_Share group or remove that group's unnecessary Read permission from the folder ACL

  2. B

    Add an explicit Deny entry for the user on the folder so it overrides all other permissions

  3. C

    Disable inheritance on the folder and manually assign Full Control only to the Finance group

  4. D

    Change the share permission to Everyone: Full Control and rely only on NTFS permissions later

Show answer and explanation

Correct answer: A

Explanation

This question tests the ability to evaluate effective permissions and identify how ACLs and group memberships combine to grant access. In Windows environments, access to files and folders is often determined by NTFS ACLs, and users can inherit permissions through multiple group memberships. The most secure and maintainable response is to remove unnecessary permissions at their source, aligning with the principle of least privilege. Explicit Deny entries can be useful in limited cases, but Microsoft and common administrative best practices generally favor simplifying group membership and ACL design rather than adding Deny rules to counteract excessive access. Security+ expects candidates to recognize that permission sprawl often comes from legacy groups and that correcting group-based access is usually better than implementing a workaround.

  • A. Correct.

    Correct. The user's continued access is caused by an additional allow permission through group membership in All_Dept_Share. The best least-privilege fix is to remove the unnecessary source of access, either by removing the user from that legacy group if membership is no longer appropriate or by removing that group's unneeded Read permission from the folder ACL. This addresses the root cause instead of layering on exceptions. In Windows, effective permissions are commonly the result of cumulative allow permissions from multiple group memberships.

  • B. Incorrect.

    Incorrect. An explicit Deny can override allows, but using Deny entries for routine access changes is generally not the preferred first step because it adds complexity and can create troubleshooting problems later. Best practice is to remove unnecessary permissions rather than block them with Deny unless there is a specific exception that must be enforced. Many administrators choose this because they know Deny takes precedence, but precedence does not make it the most maintainable solution.

  • C. Incorrect.

    Incorrect. Disabling inheritance and manually rebuilding permissions may remove legitimate inherited access for other users and groups, creating unnecessary administrative overhead and risk. The problem described is not caused by inheritance itself; it is caused by an unintended allow entry through a legacy group. Least privilege favors targeted remediation over broad restructuring of ACLs.

  • D. Incorrect.

    Incorrect. Setting the share permission to Everyone: Full Control is overly permissive and does not resolve the underlying issue in a secure way. While Windows access across the network is influenced by both share and NTFS permissions, broadening share permissions increases exposure and violates least privilege. Candidates may choose this if they recall that the most restrictive combination of share and NTFS applies, but intentionally making one layer too permissive is not a best practice.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam