โ† All CSA Flashcard Decks

Access Control Rules (ACLs) Flashcards

7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control Rules (ACLs) flashcards as text
  1. Which ServiceNow module allows administrators to view all ACL rules configured in the instance?

    Answer: System Security > Access Control List

    The Access Control List module under System Security displays all configured ACL rules in the instance for review and management.

  2. A user with the 'admin' role is denied access by an ACL. What is the most likely reason?

    Answer: ACL denials for admins occur only in scoped applications

    In scoped applications, ACLs can restrict even admin users because application scope boundaries enforce their own access rules independently.

  3. What is the purpose of the '*' (wildcard) table name in an ACL rule?

    Answer: It creates a global fallback ACL that applies when no specific table ACL matches

    An ACL with '*' as the table name acts as a global fallback, applying its conditions to any table or operation that doesn't have a more specific ACL defined.

  4. What does the 'Active' checkbox on an ACL rule control?

    Answer: Whether the ACL is included in access evaluation for the specified table and operation

    Unchecking 'Active' on an ACL effectively disables it, removing it from access evaluation without deleting the rule configuration.

  5. How should an administrator grant a specific user access to a table record without modifying roles or creating broad ACL rules?

    Answer: Create a user-specific ACL with the user's sys_id in the script condition

    A targeted ACL script condition checking gs.getUser().getID() against a specific user sys_id grants granular, user-specific record access without broader permission changes.

  6. Which of the following best describes the difference between an ACL 'condition' and an ACL 'script' in ServiceNow?

    Answer: Conditions use filter syntax and evaluate field values; scripts use JavaScript for complex logic

    ACL conditions use the condition builder with filter syntax to evaluate record field values, while scripts use JavaScript for logic that conditions can't express.

  7. What is the effect of enabling the 'Elevated privilege' option on an ACL rule?

    Answer: The ACL grants access only to users who have explicitly elevated to the security_admin role

    An ACL with 'Elevated privilege' required will only grant access to users who have actively elevated their session to the security_admin role, adding an extra layer of protection.