Access Control Lists (ACL) Practice Test — Questions and Answers
Question 1: What is the 'mask' entry in a POSIX ACL?
- The maximum effective permissions for named users, groups, and other ACL entries (Correct answer)
- An inherited permission from the parent directory
- A permissions filter applied only to the file owner
- A default permission applied to all new files
Correct answer: The maximum effective permissions for named users, groups, and other ACL entries
The mask entry defines the upper limit of effective permissions that can be granted to named users, named groups, and the owning group in a POSIX ACL.
Question 2: A company's ACL requires that passwords stored in the database use 'key stretching.' Which algorithm is specifically designed for this purpose?
- CRC32
- MD5
- SHA-1
- bcrypt (Correct answer)
Correct answer: bcrypt
bcrypt is a password hashing function designed for key stretching; it incorporates a work factor that makes brute-force attacks computationally expensive.
Question 3: Which Linux file permission octal value grants the owner read and write access while allowing only read access to group and others?
- 777
- 755
- 644 (Correct answer)
- 700
Correct answer: 644
Octal 644 grants the owner read and write (6), and grants group and others read-only access (4), which is the standard for most configuration files.
Question 4: An ACL is applied with 'ip access-group 110 in' on an interface. What does 'in' specify?
- Traffic that bypasses the ACL
- Traffic that is dropped by the ACL
- Traffic leaving the router toward the internet
- Traffic entering the router interface from the network (Correct answer)
Correct answer: Traffic entering the router interface from the network
The 'in' keyword means the ACL filters traffic as it enters the router interface from the connected network segment.
Question 5: What happens when both an AWS Identity-Based Policy and a Resource-Based Policy exist for the same action, and neither has an explicit Deny?
- The identity-based policy always wins
- The resource-based policy always takes precedence
- Access is denied by default unless at least one policy allows it
- Access is granted if either policy allows it (Correct answer)
Correct answer: Access is granted if either policy allows it
When both policy types exist without explicit denies, access is granted if either the identity-based or resource-based policy allows the action.
Question 6: In OpenLDAP ACL syntax, what does the 'by' clause specify?
- The time of day the rule is active
- The type of attribute being controlled
- Who the access rule applies to, such as specific users, authenticated users, or anonymous connections (Correct answer)
- The LDAP object or attribute being protected
Correct answer: Who the access rule applies to, such as specific users, authenticated users, or anonymous connections
The 'by' clause in an OpenLDAP ACL defines who the permission applies to, supporting specifiers like `users`, `anonymous`, `self`, or specific DNs.
Question 7: A company's ACL was modified by an attacker to allow inbound traffic on port 3389. What post-incident change control practice prevents recurrence?
- Disable remote management protocols entirely
- Require multi-person authorization and audit logging for ACL changes (Correct answer)
- Store ACL backups only on the affected device
- Allow any administrator to modify ACLs without approval
Correct answer: Require multi-person authorization and audit logging for ACL changes
Dual-authorization and immutable audit logs for ACL changes create accountability and detect unauthorized modifications early.
Question 8: In Active Directory, what is an Access Control Entry (ACE)?
- An individual permission rule specifying a trustee and the access rights granted or denied (Correct answer)
- A Group Policy Object that controls login permissions
- A certificate used to authenticate domain users
- A Kerberos ticket granting access to domain resources
Correct answer: An individual permission rule specifying a trustee and the access rights granted or denied
An ACE is a single entry within an ACL that identifies a trustee (user, group, or computer) and specifies which access rights are allowed or denied for that trustee.
Question 9: When adding a new rule to a numbered standard ACL on a Cisco router that already has entries, where is the new rule inserted by default?
- At the end of the ACL before the implicit deny (Correct answer)
- In numerical sequence based on the rule number
- After the first permit statement
- At the beginning of the ACL
Correct answer: At the end of the ACL before the implicit deny
New entries added to a numbered ACL are appended at the end of the list; to insert rules in a specific position, a named ACL with sequence numbers must be used.
Question 10: Which factor is most important for effective delegation in Access Control Lists?
- Assigning tasks to the newest team member
- Keeping all important tasks for yourself
- Matching tasks to team members' skills and development goals (Correct answer)
- Delegating only unpleasant tasks
Correct answer: Matching tasks to team members' skills and development goals
Effective delegation considers team members' current skills and development goals to ensure tasks are completed well and people grow.
Question 11: In a Zero Trust model, what does continuous validation mean?
- Validating SSL certificates at session initiation only
- Running antivirus scans on all devices every hour
- Re-authenticating and re-authorizing users and devices throughout their session (Correct answer)
- Continuously updating firewall rule sets with new threat intelligence
Correct answer: Re-authenticating and re-authorizing users and devices throughout their session
Continuous validation means that trust is not granted once at login but is repeatedly verified throughout a session based on behavior, device posture, and contextual signals.
Question 12: What does the 'ForceChangePassword' ACE enable in Active Directory?
- Requiring all domain users to change passwords at next logon
- Automatically expiring passwords for accounts in a specific OU
- The right to reset a user's password without knowing their current password (Correct answer)
- Forcing password complexity requirements on a specific account
Correct answer: The right to reset a user's password without knowing their current password
ForceChangePassword grants the ability to reset another user's password without needing their current password, making it a helpdesk delegation tool and a potential ACL abuse vector.
Question 13: A security team discovers that a time-based ACL was incorrectly configured, allowing unauthorized access during off-hours. Which recovery action directly addresses this?
- Correct the time-range definition and verify NTP synchronization on all devices (Correct answer)
- Disable the network during off-hours
- Replace time-based ACLs with static permit rules
- Remove all time-based ACLs from the network
Correct answer: Correct the time-range definition and verify NTP synchronization on all devices
Fixing the time-range definition and ensuring NTP accuracy guarantees the time-based ACL enforces the correct schedule.
Question 14: In a multi-cloud ACL strategy, which approach best ensures consistent access control enforcement across AWS, Azure, and GCP?
- Apply ACLs only at the application layer
- Use each cloud provider's native tools independently
- Implement a Cloud Security Posture Management (CSPM) tool with unified policy engine (Correct answer)
- Rely on network-level firewall rules only
Correct answer: Implement a Cloud Security Posture Management (CSPM) tool with unified policy engine
CSPM tools provide a centralized policy engine that translates and enforces consistent ACL rules across multiple cloud providers.
Question 15: In a mandatory access control (MAC) system, who controls access to resources?
- Access is determined by group membership in Active Directory
- End users can grant access to peers as needed
- A central authority enforces policy based on classification labels (Correct answer)
- The resource owner sets all access policies
Correct answer: A central authority enforces policy based on classification labels
MAC systems rely on a central authority that enforces access based on security labels and classifications, not individual owner discretion.
Question 16: In attribute-based access control (ABAC), access decisions are made based on which of the following?
- The discretion of the resource owner at time of request
- Only the user's group membership
- Predefined role assignments stored in a central database
- Attributes of the user, resource, environment, and action being requested (Correct answer)
Correct answer: Attributes of the user, resource, environment, and action being requested
ABAC evaluates multiple attributes—user attributes, resource attributes, environmental conditions, and the action—to make fine-grained access decisions.
Question 17: What does the 'WriteDACL' permission allow an attacker to do in Active Directory?
- Read all attributes of an AD object
- Create new Organizational Units in the domain
- Reset the password of any domain user
- Modify the DACL of an object to grant themselves additional permissions (Correct answer)
Correct answer: Modify the DACL of an object to grant themselves additional permissions
WriteDACL allows a principal to modify an object's DACL, enabling an attacker to grant themselves additional rights such as Full Control over that object.
Question 18: What is the role of a code of conduct in Access Control Lists practice?
- It is optional and rarely enforced
- It establishes expected behavioral and professional standards (Correct answer)
- It only applies to new employees
- It replaces all laws and regulations
Correct answer: It establishes expected behavioral and professional standards
A code of conduct sets clear expectations for professional behavior, guiding practitioners in their daily activities and decisions.
Question 19: A router has two ACLs: ACL 10 (standard) applied inbound and ACL 110 (extended) applied outbound on the same interface. A packet arrives. Which ACL is processed first?
- Both ACLs are processed simultaneously
- ACL 10 (inbound) is processed first as the packet enters the interface (Correct answer)
- ACL 110 (extended) always takes priority over standard ACLs
- ACL 110 (outbound) is processed first to determine if the packet should enter the router
Correct answer: ACL 10 (inbound) is processed first as the packet enters the interface
Inbound ACLs are evaluated as the packet arrives on the interface before the router makes a routing decision; outbound ACLs are evaluated after routing on the egress interface.
Question 20: What is a System Access Control List (SACL) used for in Windows?
- Auditing and logging access attempts to secured objects (Correct answer)
- Controlling which users can log into the system
- Managing network access to shared resources
- Defining system-level file permissions for administrators
Correct answer: Auditing and logging access attempts to secured objects
A SACL specifies the types of access attempts that generate audit log entries, enabling security monitoring and compliance tracking in Windows environments.
Question 21: How can an organization ensure ACLs are effectively implemented?
- Only review ACLs annually
- Disable firewall integration
- Document rules and monitor ACL logs (Correct answer)
- Ignore access control rules
Correct answer: Document rules and monitor ACL logs
To ensure ACLs are effectively implemented, organizations should meticulously document all ACL rules, including their purpose and expected behavior. Additionally, monitoring ACL logs is vital, as logs provide real-time insights into traffic that is being permitted or denied, helping to detect policy violations, security incidents, and potential misconfigurations.
Question 22: What does running `getfacl -R /data` accomplish on a Linux system?
- Generates a report of files with no ACL entries under /data
- Recursively displays the ACL entries for all files and directories under /data (Correct answer)
- Resets all ACLs under /data to default values
- Removes named user ACL entries from /data and its subdirectories
Correct answer: Recursively displays the ACL entries for all files and directories under /data
The `-R` flag makes `getfacl` operate recursively, displaying the ACL entries for every file and directory within the specified path.
Question 23: Which type of ACL is evaluated BEFORE routing decisions are made on a Cisco router?
- Inbound interface ACL (Correct answer)
- VLAN ACL
- Route-map ACL
- Outbound interface ACL
Correct answer: Inbound interface ACL
Inbound ACLs are processed as packets arrive on an interface, before the router makes a routing table lookup decision.
Question 24: An administrator sees 'access-list 1 permit 0.0.0.0 255.255.255.255' in the config. What traffic does this match?
- Only traffic destined to the broadcast address
- No traffic, as this is an invalid ACE
- Only traffic from the host 0.0.0.0
- All IP traffic from any source address (Correct answer)
Correct answer: All IP traffic from any source address
The combination of source address 0.0.0.0 and wildcard 255.255.255.255 matches all 32 bits as 'don't care,' which is equivalent to 'any' and permits all traffic.
Question 25: An extended ACL uses the keyword 'any' in the source field. What does this represent?
- 0.0.0.0 with wildcard mask 255.255.255.255 (Correct answer)
- The network's default gateway address
- 0.0.0.0 with wildcard mask 0.0.0.0
- 255.255.255.255 with wildcard mask 0.0.0.0
Correct answer: 0.0.0.0 with wildcard mask 255.255.255.255
'any' is shorthand for source address 0.0.0.0 with wildcard mask 255.255.255.255, which matches every possible IP address.
Question 26: What is a 'shadow ACL' risk in cloud security architecture?
- ACL rules copied from on-premises firewalls without review
- Unintended permissions granted through inherited or wildcard ACL rules that bypass intended restrictions (Correct answer)
- Firewall rules that only apply during business hours
- ACL logs that are obscured by encryption
Correct answer: Unintended permissions granted through inherited or wildcard ACL rules that bypass intended restrictions
Shadow ACLs occur when overly broad wildcard rules or inherited permissions grant unintended access that bypasses more specific restrictive rules.
Question 27: Which Linux ACL feature allows setting different permissions for multiple individual users on the same file?
- Named user ACL entries configured via setfacl (Correct answer)
- Group ownership changes with chgrp
- chmod with multiple flags
- Umask configuration in the shell profile
Correct answer: Named user ACL entries configured via setfacl
Named user ACL entries, set with `setfacl -m u:username:permissions`, allow distinct permissions to be assigned to multiple individual users on a single file beyond the standard owner/group/others model.
Question 28: What does SAML (Security Assertion Markup Language) primarily enable in identity management?
- Encrypting directory service queries between servers
- Defining ACL rules in an XML-based format
- Auditing privileged user sessions in real time
- Federated single sign-on by exchanging authentication assertions between parties (Correct answer)
Correct answer: Federated single sign-on by exchanging authentication assertions between parties
SAML enables federated SSO by allowing an identity provider to pass authentication and authorization assertions to service providers.
Question 29: Which AWS Organization feature allows enforcing ACL guardrails across all member accounts simultaneously?
- Service Control Policies (SCPs) (Correct answer)
- AWS Trusted Advisor
- AWS Config Rules
- IAM Permission Boundaries
Correct answer: Service Control Policies (SCPs)
SCPs applied at the AWS Organization level create guardrails that restrict what actions member accounts can perform, even for their root users.
Question 30: A security team receives a threat intelligence report with a list of 500 malicious IPs. What is the most scalable method to implement these as ACL deny rules on Cisco IOS?
- Use a dynamic ACL pulled from a RADIUS server
- Configure SNMP traps for each IP
- Use IP prefix-lists or object-groups to aggregate the entries efficiently (Correct answer)
- Manually enter each IP as a separate ACL line
Correct answer: Use IP prefix-lists or object-groups to aggregate the entries efficiently
Object-groups (on ASA/IOS-XE) or IP prefix-lists allow administrators to manage large sets of addresses efficiently without creating an unmanageable number of individual ACL lines.
Question 31: Which Windows interface provides a GUI to manage NTFS file and folder permissions?
- File Explorer Properties > Security tab (Correct answer)
- Device Manager
- Task Manager
- Registry Editor
Correct answer: File Explorer Properties > Security tab
The Security tab in a file or folder's Properties dialog in Windows File Explorer provides a graphical interface for managing NTFS ACL permissions.
Question 32: An organization must document ACL rule justifications as part of a compliance audit. Which regulatory framework most explicitly requires that firewall and ACL rules be accompanied by documented business justifications?
- CAN-SPAM Act
- FERPA
- PCI DSS (Correct answer)
- COPPA
Correct answer: PCI DSS
PCI DSS Requirement 1.2.1 explicitly requires that every ACL and firewall rule restricting inbound and outbound traffic be accompanied by a documented business justification.
Question 33: In POSIX-based systems, which command displays the Access Control List entries for a file?
- getfacl (Correct answer)
- chown
- chmod
- ls -l
Correct answer: getfacl
The `getfacl` command displays the ACL entries of files on POSIX-compliant systems.
Question 34: What is 'privilege creep' in identity and access management?
- A sudden spike in privileged account usage detected by SIEM
- The gradual accumulation of access rights beyond what a user currently needs (Correct answer)
- An exploit that escalates a standard user to administrator
- The practice of logging all privileged user activities
Correct answer: The gradual accumulation of access rights beyond what a user currently needs
Privilege creep occurs when users accumulate access rights over time—often through role changes—without removing previously granted permissions.
Question 35: Which ACL-related cloud security concept ensures that service accounts and roles have only the permissions needed for their specific task?
- Need-to-know basis
- Defense in depth
- Principle of least privilege (Correct answer)
- Separation of duties
Correct answer: Principle of least privilege
The principle of least privilege limits ACL grants to the minimum permissions required, reducing the blast radius of a compromised credential.
Question 36: What does the Windows `icacls` command do?
- Displays and modifies NTFS access control lists on files and directories (Correct answer)
- Lists installed certificates
- Configures IP address ACLs on network interfaces
- Manages Internet Connection settings
Correct answer: Displays and modifies NTFS access control lists on files and directories
`icacls` is a Windows command-line tool used to view and modify NTFS discretionary access control lists on files and directories.
Question 37: What is the role of documentation in Cloud Security Architecture for Access Control Lists?
- It is unnecessary paperwork
- It should only be done monthly
- It provides an accurate record for accountability and reference (Correct answer)
- It is only for management review
Correct answer: It provides an accurate record for accountability and reference
Proper documentation in Cloud Security Architecture ensures accountability, traceability, and serves as a reference for future decisions.
Question 38: In a filesystem ACL, what does a 'mask' entry control?
- The minimum permissions required for all users to access the file
- The maximum permissions that can be granted to the file owner
- The maximum effective permissions for named users, named groups, and the owning group (Correct answer)
- The permissions applied when no other ACL entry matches
Correct answer: The maximum effective permissions for named users, named groups, and the owning group
The POSIX ACL mask entry limits the maximum effective permissions for named users, named groups, and the owning group, acting as an upper bound.
Question 39: Under GLBA (Gramm-Leach-Bliley Act), financial institutions must protect customer financial data. Which ACL design supports GLBA's Safeguards Rule?
- Using ACLs only on DMZ interfaces, not internal segments
- Allowing all branch office traffic to headquarters financial servers
- Segmented network zones with ACLs restricting access to customer financial data to only authorized applications and staff (Correct answer)
- A single flat network with logging to detect breaches after the fact
Correct answer: Segmented network zones with ACLs restricting access to customer financial data to only authorized applications and staff
GLBA's Safeguards Rule requires implementing access controls including network segmentation to protect customer financial information from unauthorized access.
Question 40: In Linux extended ACLs, what does a 'default ACL' on a directory do?
- Sets a fallback permission when no ACL entry matches
- Defines permissions applied to new files and subdirectories created within that directory (Correct answer)
- Restricts the file owner's permissions
- Removes all ACL entries from the directory
Correct answer: Defines permissions applied to new files and subdirectories created within that directory
Default ACLs on directories specify the permission template automatically applied to newly created files and subdirectories within that directory.
Question 41: What does the term 'provisioning' refer to in identity management?
- Revoking access when an employee leaves
- Encrypting user credentials in a directory
- The process of creating and assigning user accounts and access rights (Correct answer)
- Auditing user activity logs for compliance
Correct answer: The process of creating and assigning user accounts and access rights
Provisioning is the process of setting up user identities and granting them the appropriate access rights to systems and resources.
Question 42: What is the primary role of a firewall in combination with ACLs?
- Monitor and filter network traffic (Correct answer)
- Convert IP addresses to hostnames
- Manage domain names
- Increase internet speed
Correct answer: Monitor and filter network traffic
Firewalls and ACLs both play a critical role in monitoring and filtering network traffic, often working in conjunction. While ACLs are typically configured on routers and switches for basic packet filtering, firewalls offer more advanced stateful inspection and application-layer filtering. Together, they enforce comprehensive security policies by controlling what traffic can enter or leave a network.
Question 43: How does microsegmentation differ from traditional VLAN-based network segmentation?
- Microsegmentation is only applicable to cloud environments, while VLANs work on-premises only
- Microsegmentation operates at Layer 7, while VLANs operate at Layer 2
- Microsegmentation provides workload-level granularity, while VLANs segment at the subnet level (Correct answer)
- Microsegmentation requires physical hardware changes, while VLANs are purely software-defined
Correct answer: Microsegmentation provides workload-level granularity, while VLANs segment at the subnet level
Microsegmentation enforces policies at the individual workload or application level, providing far more granular control than VLANs, which segment traffic at the broader network or subnet level.
Question 44: In Windows NTFS, which permission level grants read, write, and delete rights but excludes the ability to change permissions or take ownership?
- Modify (Correct answer)
- Read & Execute
- Full Control
- Write
Correct answer: Modify
The Modify permission allows reading, writing, and deleting files but does not include rights to change permissions or take ownership.
Question 45: What is the role of a Cloud Access Security Broker (CASB) in relation to cloud ACLs?
- It generates network ACL rules automatically from traffic analysis
- It enforces ACL policies between users and cloud services, providing visibility and control (Correct answer)
- It manages SSL certificates for cloud endpoints
- It replaces native cloud IAM systems entirely
Correct answer: It enforces ACL policies between users and cloud services, providing visibility and control
A CASB sits between users and cloud services to enforce ACL-style policies, detect violations, and provide audit logging for cloud access.
Question 46: What is the purpose of the 'Protected Users' security group in Active Directory?
- Applies authentication restrictions to reduce credential theft exposure for sensitive accounts (Correct answer)
- Disables interactive logon for service accounts
- Restricts logon hours for administrative accounts
- Prevents group members from being added to privileged groups
Correct answer: Applies authentication restrictions to reduce credential theft exposure for sensitive accounts
Accounts in the Protected Users group cannot use NTLM, DES, or RC4 Kerberos encryption, and credentials are not cached, significantly reducing the attack surface for credential-based attacks.
Question 47: What happens when a packet matches an ACL rule that has the 'log-input' keyword on a Cisco router?
- The packet is dropped and the CPU generates a debug trace
- The syslog message includes the input interface and source MAC address in addition to the IP information (Correct answer)
- The router generates an SNMP trap but does not log locally
- The packet is duplicated and sent to a logging server
Correct answer: The syslog message includes the input interface and source MAC address in addition to the IP information
'log-input' provides more detail than 'log' by also recording the receiving interface and Layer 2 source MAC address in the syslog message.
Question 48: An ACL is configured to deny traffic from 10.0.0.0/8 but a host at 10.5.5.5 must be permitted. How should the ACEs be ordered?
- Place both entries simultaneously using the 'or' keyword
- Order does not matter since all entries are evaluated
- Place the deny 10.0.0.0/8 entry first, then the permit for 10.5.5.5
- Place the permit host 10.5.5.5 entry first, then the deny 10.0.0.0/8 entry (Correct answer)
Correct answer: Place the permit host 10.5.5.5 entry first, then the deny 10.0.0.0/8 entry
The more specific permit for host 10.5.5.5 must appear before the broader deny for 10.0.0.0/8, otherwise the host would be denied before reaching the permit statement.
Question 49: Which command verifies which ACLs are applied to a specific router interface?
- show running-config access-list
- show ip interface (Correct answer)
- show access-lists
- debug ip access-list
Correct answer: show ip interface
'show ip interface' displays the inbound and outbound ACLs applied to each interface along with other IP interface statistics.
Question 50: Which attribute in Active Directory stores the security descriptor (including DACL) that controls access to an object's attributes?
- objectClass
- nTSecurityDescriptor (Correct answer)
- memberOf
- userAccountControl
Correct answer: nTSecurityDescriptor
The `nTSecurityDescriptor` attribute contains the complete security descriptor for every AD object, including the DACL that governs who can read, write, or otherwise interact with it.
Question 51: In cloud security architecture, what does 'micro-segmentation' achieve that traditional perimeter ACLs cannot?
- Elimination of the need for encryption
- Faster packet processing at the network edge
- Granular east-west traffic controls between individual workloads (Correct answer)
- Simplified ACL rule management
Correct answer: Granular east-west traffic controls between individual workloads
Micro-segmentation applies ACL controls between individual workloads inside the data center or cloud VPC, limiting lateral movement after a breach.
Question 52: Which IAM concept ensures that no single user has enough privileges to complete a sensitive transaction alone?
- Least privilege
- Account lockout
- Need-to-know
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Separation of duties requires that critical tasks be split among multiple users to prevent fraud or error by any one individual.
Question 53: Which POSIX ACL entry type covers users who are not the file owner and do not match any named user or group entry?
- mask
- group
- user
- other (Correct answer)
Correct answer: other
The 'other' ACL entry type defines permissions for users who are neither the owner nor match any named user or group in the ACL.
Question 54: Which concept in zero-trust architecture directly replaces the traditional 'trust but verify' perimeter model?
- Trusting all traffic that originates from within the corporate VPN
- Implicit trust within internal network segments
- Granting access based solely on IP address allow-lists
- Never trust, always verify—regardless of network location (Correct answer)
Correct answer: Never trust, always verify—regardless of network location
Zero trust mandates that no user or device is trusted by default, even inside the network perimeter—every access request must be verified.
Question 55: After discovering a security breach caused by a misconfigured ACL, what is the FIRST remediation step an administrator should take?
- Delete all existing ACLs and start fresh
- Notify all users of the breach immediately
- Upgrade all network hardware
- Identify and isolate affected network segments (Correct answer)
Correct answer: Identify and isolate affected network segments
Isolating affected segments prevents further lateral movement while preserving evidence for forensic analysis.
Question 56: In AWS, which service acts as the central ACL enforcement point for cross-account resource access?
- AWS CloudTrail
- AWS Config
- AWS IAM with resource-based policies (Correct answer)
- AWS Shield
Correct answer: AWS IAM with resource-based policies
IAM resource-based policies with Principal elements allow cross-account access by explicitly naming trusted accounts or roles.
Question 57: Which IAM control is specifically designed to verify that user access rights remain appropriate over time?
- Multi-factor authentication
- Password complexity policy
- Access certification (user access review) (Correct answer)
- Single sign-on
Correct answer: Access certification (user access review)
Access certification is a periodic review process where managers verify that users still need and are authorized for their current access rights.
Question 58: What does NTFS stand for in the context of Windows file system security?
- Native Text File Standard
- Network Transfer File System
- Network Time File Server
- New Technology File System (Correct answer)
Correct answer: New Technology File System
NTFS (New Technology File System) is Microsoft's proprietary file system that supports fine-grained ACL permissions.
Question 59: Which property ensures that an encrypted message cannot be linked to the plaintext even if an attacker sees multiple ciphertexts of the same message?
- Key escrow
- Semantic security (IND-CPA) (Correct answer)
- Non-repudiation
- Perfect forward secrecy
Correct answer: Semantic security (IND-CPA)
IND-CPA (indistinguishability under chosen-plaintext attack) ensures that encrypting the same plaintext twice yields ciphertexts that an attacker cannot distinguish.
Question 60: A packet arrives at a router with an ACL containing 15 ACEs. The packet matches ACE #7 which denies it. What happens to ACEs 8–15?
- They are checked only if ACE #7 has the 'continue' keyword
- They are skipped because processing stops at the first match (Correct answer)
- They are all checked in sequence before dropping the packet
- They override ACE #7 if any permit the packet
Correct answer: They are skipped because processing stops at the first match
ACL processing is top-down and stops at the first matching ACE; once a packet matches ACE #7, the remaining ACEs are not evaluated.
Question 61: When testing ACLs protecting a Voice over IP (VoIP) network, which UDP port range should a tester specifically verify is properly restricted to trusted sources only?
- UDP 161-162 (SNMP)
- UDP 53 (DNS)
- UDP 80-443
- UDP 16384-32767 (RTP media streams) and UDP 5060 (SIP signaling) (Correct answer)
Correct answer: UDP 16384-32767 (RTP media streams) and UDP 5060 (SIP signaling)
RTP uses UDP ports 16384-32767 for media and SIP uses UDP 5060 for signaling; unrestricted access to these ports allows toll fraud, eavesdropping, and denial of service attacks against VoIP infrastructure.
Question 62: When NTFS 'Allow' and 'Deny' permissions conflict for the same user, which takes precedence?
- The most recently set permission wins
- Allow always wins
- Deny always wins (Correct answer)
- The administrator decides at login
Correct answer: Deny always wins
In NTFS, explicit Deny permissions always override Allow permissions to ensure restrictive security regardless of the order ACEs appear in the list.
Question 63: Which Linux command sets an ACL entry granting user 'john' read and write access to a file?
- setfacl -m u:john:rw file.txt (Correct answer)
- chmod u+rw john file.txt
- chown john:rw file.txt
- acl -set john:rw file.txt
Correct answer: setfacl -m u:john:rw file.txt
The `setfacl -m u:john:rw file.txt` command modifies the ACL to grant user john read and write permissions on the specified file.
Question 64: In GCP, which construct is equivalent to AWS Security Groups for controlling VM-level network traffic?
- Cloud NAT rules
- VPC firewall rules with target tags or service accounts (Correct answer)
- Cloud Armor policies
- Shared VPC ACLs
Correct answer: VPC firewall rules with target tags or service accounts
GCP VPC firewall rules applied via network tags or service accounts control ingress/egress traffic at the VM instance level.
Question 65: What technique do penetration testers use to bypass ACLs that block standard scanning ports by sending packets with specific TCP flags?
- ARP poisoning to redirect traffic
- DNS tunneling to exfiltrate data
- SYN flood attacks
- ACK scanning or FIN scanning to probe through stateless ACLs (Correct answer)
Correct answer: ACK scanning or FIN scanning to probe through stateless ACLs
ACK and FIN scans exploit stateless ACLs that only filter SYN packets, since these ACLs may permit non-SYN packets that appear to belong to established connections.
Question 66: Which ACL feature helps prevent unauthorized data access?
- Traffic mirroring
- Static ACL
- Standard ACL
- Time-based ACL (Correct answer)
Correct answer: Time-based ACL
A Time-based ACL helps prevent unauthorized data access by allowing administrators to define access rules that are active only during specific times or days. For example, access to sensitive servers could be restricted to business hours. This adds an extra layer of security, ensuring resources are protected when they are most vulnerable or when access is not required.
Question 67: An ACL is configured with the 'log-input' keyword instead of 'log'. What additional information does 'log-input' provide?
- TTL value of matched packets
- TCP flags of matched packets
- Destination MAC address of matched packets
- Input interface and source MAC address (Correct answer)
Correct answer: Input interface and source MAC address
The 'log-input' keyword records the input interface and, for non-tunnel interfaces, the source MAC address in addition to standard log fields.
Question 68: Which cloud ACL model evaluates permissions at the resource level rather than at the identity level?
- Attribute-Based Access Control
- Resource-Based Policy (Correct answer)
- Mandatory Access Control
- Role-Based Access Control
Correct answer: Resource-Based Policy
Resource-based policies are attached directly to cloud resources (e.g., S3 buckets) and define who can access that specific resource.
Question 69: A SOC playbook requires automated ACL-based blocking of IPs identified as malicious by a threat intelligence feed. Which technology best enables this automation?
- Manual ACL updates pushed via Telnet scripts
- Scheduled SNMP polling to update ACL tables
- SOAR platform integration with network devices via API or NETCONF to push ACL changes (Correct answer)
- Static ACL entries updated weekly during maintenance windows
Correct answer: SOAR platform integration with network devices via API or NETCONF to push ACL changes
SOAR platforms can orchestrate automated responses by pushing ACL updates to routers and firewalls via APIs, NETCONF, or RESTCONF in near real-time based on threat intelligence.
Question 70: When configuring an extended ACL on a Cisco router, where is it best practice to place it?
- At the core layer of the network hierarchy
- As close to the source as possible (Correct answer)
- As close to the destination as possible
- On the default gateway of the destination network
Correct answer: As close to the source as possible
Extended ACLs should be placed close to the source to block unwanted traffic early and avoid consuming unnecessary bandwidth.
Question 71: What is the function of a Policy Decision Point (PDP) in Zero Trust Architecture?
- It evaluates access requests against policies and grants or denies access (Correct answer)
- It encrypts data in transit between network segments
- It monitors network traffic for anomalous behavior patterns
- It manages digital certificates for device authentication
Correct answer: It evaluates access requests against policies and grants or denies access
The Policy Decision Point (PDP) evaluates access requests by comparing them against defined policies, determining whether to grant or deny access before the Policy Enforcement Point acts on that decision.
Question 72: When designing cloud ACLs for a PCI DSS-compliant environment, what is the minimum segmentation requirement for the cardholder data environment (CDE)?
- VPN tunnels replace the need for ACL segmentation
- No segmentation required if encryption is used
- Firewall ACLs must isolate the CDE from all other network zones (Correct answer)
- Application-layer authentication alone satisfies PCI segmentation
Correct answer: Firewall ACLs must isolate the CDE from all other network zones
PCI DSS requires firewall-based network segmentation to isolate the CDE from untrusted networks and reduce the scope of compliance requirements.
Question 73: What is a Discretionary Access Control List (DACL) in Windows security?
- A list of system-defined rules that cannot be modified by users
- An ACL that the object owner can modify to control access by users and groups (Correct answer)
- A mandatory access control list enforced by the OS kernel
- A list of denied users maintained by the domain controller
Correct answer: An ACL that the object owner can modify to control access by users and groups
A DACL is the portion of a Windows security descriptor that the object's owner controls, specifying which trustees have access and the type of access permitted.
Question 74: Which type of ACL filters traffic based on IP addresses and protocols?
- Dynamic ACL
- Role-Based ACL
- Standard ACL
- Extended ACL (Correct answer)
Correct answer: Extended ACL
An Extended ACL provides granular control over network traffic by filtering packets based on a wider range of criteria compared to a Standard ACL. It can filter traffic using source and destination IP addresses, specific protocols (like TCP, UDP, ICMP), and even port numbers. This allows for highly specific and flexible security policies, enabling precise control over network access and services.
Question 75: What does risk mitigation mean in Access Control Lists practice?
- Accepting all risks without action
- Eliminating all risks completely
- Ignoring low-level risks
- Taking steps to reduce the likelihood or impact of identified risks (Correct answer)
Correct answer: Taking steps to reduce the likelihood or impact of identified risks
Risk mitigation involves implementing strategies to reduce either the probability of a risk occurring or its potential impact.
Question 76: An ACL log shows repeated permit hits on port 443 from a single external IP at 3-second intervals over 6 hours. What threat does this most likely indicate?
- Automated beacon or C2 check-in traffic (Correct answer)
- Distributed denial-of-service attack
- BGP route injection attempt
- Legitimate user session with keep-alive
Correct answer: Automated beacon or C2 check-in traffic
Regular, timed connections from a single host are a hallmark of malware beaconing to a command-and-control server.
Question 77: What is the 'shadow credentials' attack technique in Active Directory?
- Stealing Kerberos service tickets from memory using Mimikatz
- Abusing write access to the msDS-KeyCredentialLink attribute to obtain a TGT for the target account (Correct answer)
- Creating volume shadow copies of sensitive AD databases
- Using stolen NTLM hashes to authenticate as another user
Correct answer: Abusing write access to the msDS-KeyCredentialLink attribute to obtain a TGT for the target account
Shadow credentials attacks exploit GenericWrite or WriteProperty ACE on the `msDS-KeyCredentialLink` attribute to add a certificate-based credential, then use PKINIT to obtain a TGT for the target account.
Question 78: What is an 'orphan account' in the context of identity lifecycle management?
- An account shared among multiple users for administrative tasks
- An account with no password set
- A guest account created for temporary contractor access
- A user account that remains active after the associated employee has left the organization (Correct answer)
Correct answer: A user account that remains active after the associated employee has left the organization
Orphan accounts are active user accounts that are no longer associated with a current employee, creating a security risk if not deprovisioned.
Question 79: In an ACL ruleset, traffic is permitted only over port 443. Which encryption protocol operates on this port by default?
- HTTPS (TLS) (Correct answer)
- FTPS
- IPsec IKE
- SSH
Correct answer: HTTPS (TLS)
HTTPS uses TLS and operates on TCP port 443 by default, providing encrypted and authenticated web communications.
Question 80: What is the primary purpose of an Identity Provider (IdP) in a federated identity system?
- To authenticate users and assert their identity to service providers (Correct answer)
- To store user passwords in an encrypted database
- To monitor network traffic for unauthorized access attempts
- To authorize access to specific application features
Correct answer: To authenticate users and assert their identity to service providers
An IdP authenticates users and issues identity assertions (tokens or assertions) that other service providers trust.
Question 81: Which of the following is a key characteristic of discretionary access control (DAC)?
- Access levels are determined by government classification labels
- Users cannot modify access permissions under any circumstances
- Resource owners can grant or restrict access to their own resources (Correct answer)
- Access is controlled exclusively by a system-wide security policy
Correct answer: Resource owners can grant or restrict access to their own resources
In DAC, the owner of a resource has discretion over who can access it and can set permissions accordingly.
Question 82: An organization detects lateral movement between VLANs despite inter-VLAN ACLs being in place. Which explanation is most likely?
- VLANs cannot be secured with ACLs
- The switch's MAC address table is corrupted
- VLAN tagging is disabled on all trunk ports
- An ACL is applied in the wrong direction on the Layer 3 SVI (Correct answer)
Correct answer: An ACL is applied in the wrong direction on the Layer 3 SVI
ACLs applied in the wrong direction on an SVI (e.g., inbound instead of outbound or vice versa) fail to inspect the traffic in the intended flow path.
Question 83: A Security Group in AWS is best described as which type of access control?
- Stateless packet filter
- Stateful virtual firewall ACL (Correct answer)
- Identity-based permission boundary
- Network ACL at the subnet level
Correct answer: Stateful virtual firewall ACL
Security Groups are stateful, meaning return traffic is automatically allowed without explicit outbound rules for established connections.
Question 84: What is a Software-Defined Perimeter (SDP) in the context of Zero Trust?
- A dynamic, identity-centric access control model that hides infrastructure from unauthorized users (Correct answer)
- A physical firewall appliance that enforces network boundaries
- A cloud-based VPN solution for remote workforce connectivity
- A SIEM tool that correlates security events across network segments
Correct answer: A dynamic, identity-centric access control model that hides infrastructure from unauthorized users
A Software-Defined Perimeter creates a dynamic perimeter based on user identity and device posture, making infrastructure invisible to unauthorized users until after authentication and authorization succeed.
Question 85: What is the advantage of using role-based ACLs?
- Assigns permissions based on user roles (Correct answer)
- Requires manual permission updates
- Restricts access based only on IP addresses
- Prevents changes to user access policies
Correct answer: Assigns permissions based on user roles
The main advantage of using role-based ACLs (RBACLs) is their ability to assign permissions based on predefined user roles. Instead of managing individual user permissions, administrators can define access rights for roles like 'Administrator' or 'Guest.' This simplifies access management, making it more scalable and easier to maintain consistency across many users.
Question 86: What is the recommended practice when an S3 bucket ACL conflicts with a bucket policy in AWS?
- Conflicts result in automatic denial with no evaluation
- The bucket policy always overrides the bucket ACL
- The bucket ACL always overrides the bucket policy
- AWS evaluates both, and an explicit deny in either will block access (Correct answer)
Correct answer: AWS evaluates both, and an explicit deny in either will block access
AWS evaluates all applicable policies together; an explicit Deny in any policy (ACL or bucket policy) overrides all Allows.
Access Control Lists (ACL) Practice Test
A comprehensive practice test covering Access Control Lists across networking, operating systems, identity management, cloud security, and compliance domains. Tests knowledge of ACL configuration, implementation, and management in real-world enterprise environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds