SY0-701 exam dumps

SY0-701 practice question 346 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 346

Single answerPermission assignments and implications

A security administrator is reviewing access to a shared finance folder on a Windows file server after an internal audit found that several contractors could open confidential payroll spreadsheets. The folder is located on an NTFS volume and is shared over the network. The administrator discovers the following: the share permission for the Finance share is set to Everyone: Read, and the NTFS permissions on the Payroll folder grant the Contractors group Modify. The contractors only need to read a single budget template in another folder and should not access payroll data. Which action should the administrator take FIRST to most effectively prevent the contractors from accessing the payroll spreadsheets while still supporting least privilege?

  1. A

    Remove the Contractors group from the NTFS permissions on the Payroll folder and grant access only to the specific authorized finance users/groups

  2. B

    Change the Finance share permission from Everyone: Read to Everyone: Full Control so NTFS permissions can manage access more precisely

  3. C

    Add a Deny Read permission for the Contractors group at the share level on the Finance share

  4. D

    Move the payroll spreadsheets to a different file extension and rely on user awareness training to prevent access

Show answer and explanation

Correct answer: A

Explanation

The key concept is understanding permission assignments and their implications when both share and NTFS permissions apply. For Windows shared folders, effective permissions across the network are determined by the most restrictive combination of share and NTFS permissions. In this case, Everyone: Read at the share level still permits reading, and Contractors: Modify at the NTFS level is excessive for the Payroll folder. Since contractors should not access payroll data at all, the most appropriate first step is to remove that unnecessary NTFS permission and grant access only to authorized users or groups, following least privilege and need-to-know principles. This aligns with common Microsoft guidance on shared folder access: use security groups, avoid assigning overly broad permissions, and remove unnecessary permissions rather than relying on explicit denies except when required. From a Security+ perspective, the scenario tests practical application of permission assignment review, least privilege, and the security implications of inherited or overly broad access.

  • A. Correct.

    Correct. In a Windows environment, effective access over the network is the most restrictive combination of share and NTFS permissions. Because the share grants Everyone: Read and the NTFS permission grants Contractors: Modify, contractors can still read the payroll files. Removing the unnecessary NTFS permission from the Payroll folder and assigning access only to the required finance users or groups best enforces least privilege. This directly addresses the excessive permission assignment that caused the exposure.

  • B. Incorrect.

    Incorrect. Setting the share permission to Everyone: Full Control would broaden access at the share layer, not reduce it. Although many administrators simplify share permissions and rely primarily on NTFS permissions, granting Everyone: Full Control is not the best first step in this scenario because the core problem is that Contractors already have excessive NTFS rights on the sensitive Payroll folder.

  • C. Incorrect.

    Incorrect. A deny entry can block access, but using Deny broadly is generally avoided unless there is a specific need because it can create troubleshooting complexity and unintended consequences. Also, the better corrective action is to remove the inappropriate allow permission from the Payroll folder rather than layering an explicit deny at the share level.

  • D. Incorrect.

    Incorrect. Changing file extensions does not meaningfully protect sensitive data. Users with read access could still open or rename the files, and security awareness training does not replace technical access controls. This option reflects a common misconception that obscurity or policy alone can compensate for incorrect permission assignments.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam