SY0-701 exam dumps

SY0-701 practice question 347 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 347

Single answerPermission assignments and implications

A systems administrator is reviewing access to a shared finance folder after an internal audit found that several contractors could read budget files they were not supposed to access. The folder is hosted on a Windows file server. The Share permissions are set to "Everyone: Read," and the NTFS permissions on the folder grant "Finance_Group: Modify" and "Contractors: Read." One contractor is a member of both Finance_Group and Contractors because of a temporary project assignment. The company wants that contractor to be able to update files in the finance folder for the duration of the project, while ensuring other contractors can only read files and no users receive unnecessary access. Which action best meets this requirement?

  1. A

    Remove the contractor from Contractors so the user only inherits Modify from Finance_Group

  2. B

    Change the Share permission from Everyone: Read to Everyone: Full Control and rely on NTFS permissions for restriction

  3. C

    Grant the individual contractor an explicit NTFS Deny: Write on the folder to prevent accidental modification by other contractors

  4. D

    Replace Finance_Group: Modify with Finance_Group: Full Control so project members can update files more easily

Show answer and explanation

Correct answer: A

Explanation

This question tests understanding of permission assignments, overlapping group memberships, and least privilege. In Windows environments, both Share and NTFS permissions affect network file access, and the effective permission is the most restrictive combination. NTFS Modify is usually appropriate for users who need to edit files, while Full Control is broader because it can include permission changes and ownership-related actions. Best practice is to avoid unnecessary group memberships and avoid using explicit Deny unless there is a clear need, since Deny commonly overrides Allow and can create unintended consequences. Microsoft documentation and common Windows administration guidance recommend assigning permissions to groups rather than individuals where possible, minimizing overlapping access, and using least privilege to reduce accidental exposure.

  • A. Correct.

    Correct. In Windows, effective access is determined by the combination of share and NTFS permissions, with the most restrictive result applying across the two layers for network access. Here, the current Share permission of Everyone: Read prevents write access over the network even if NTFS grants Modify. To allow the specific contractor to update files through membership in Finance_Group without broadening access for others, removing the user from the broader Contractors group eliminates unnecessary read-based group membership that is no longer needed for this scenario. This supports least privilege by avoiding overlapping assignments that can complicate effective permissions.

  • B. Incorrect.

    Incorrect. Changing the Share permission to Everyone: Full Control is a common administrative approach because administrators often simplify share permissions and enforce restriction through NTFS. However, in this scenario it does not best meet the requirement to ensure no users receive unnecessary access. Although NTFS would still restrict most users, granting Full Control at the share layer to Everyone is broader than necessary and weakens the permission model if NTFS is later misconfigured.

  • C. Incorrect.

    Incorrect. An explicit Deny overrides Allow permissions in most Windows permission evaluations. Applying Deny: Write to the individual contractor would block that user from updating files, which is the opposite of the business requirement. This option reflects the misconception that Deny can be used to fine-tune access safely without side effects; in practice, Deny entries should be used sparingly because they often create troubleshooting and access issues.

  • D. Incorrect.

    Incorrect. Full Control includes additional capabilities such as changing permissions and taking ownership, which exceed the stated need to update files. Modify is typically sufficient for creating, changing, and deleting files. Expanding the group's access to Full Control violates least privilege and could allow unauthorized permission changes.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam