Access Control Lists (ACL) Practice Test — Questions and Answers
Question 1: Where should an extended ACL be placed for optimal performance?
- As close to the source as possible (Correct answer)
- On the firewall only
- On the core router only
- As close to the destination as possible
Correct answer: As close to the source as possible
Extended ACLs should be placed close to the source so unwanted traffic is dropped early, reducing unnecessary bandwidth consumption.
Question 2: Which term describes the practice of granting users only the minimum access rights needed to perform their job functions?
- Role segmentation
- Zero trust
- Least privilege (Correct answer)
- Need-to-know
Correct answer: Least privilege
The principle of least privilege limits user access to only what is required for their specific role, reducing the attack surface.
Question 3: A company's ACL requires that passwords stored in the database use 'key stretching.' Which algorithm is specifically designed for this purpose?
- bcrypt (Correct answer)
- MD5
- CRC32
- SHA-1
Correct answer: bcrypt
bcrypt is a password hashing function designed for key stretching; it incorporates a work factor that makes brute-force attacks computationally expensive.
Question 4: In NTFS, what does 'propagation of permissions' refer to?
- Distributing permissions across multiple network shares
- Automatic application of parent folder permissions to child objects via inheritance (Correct answer)
- Manually copying permissions from one object to another
- Synchronizing permissions between domain controllers
Correct answer: Automatic application of parent folder permissions to child objects via inheritance
Permission propagation in NTFS is the automatic inheritance mechanism by which a parent folder's permissions cascade down to its child files and subfolders.
Question 5: What leadership style is most effective for building team autonomy in Access Control Lists?
- Micromanagement
- Avoidant leadership
- Autocratic leadership
- Delegative (laissez-faire) leadership for experienced teams (Correct answer)
Correct answer: Delegative (laissez-faire) leadership for experienced teams
Delegative leadership empowers experienced team members to make decisions, fostering autonomy and professional growth.
Question 6: A DACL (Downloadable ACL) is most commonly associated with which technology?
- BGP route filtering
- 802.1X port-based authentication with RADIUS (Correct answer)
- MPLS traffic engineering
- Static route filtering
Correct answer: 802.1X port-based authentication with RADIUS
DACLs are pushed from a RADIUS server to network devices after successful 802.1X authentication, dynamically applying per-user access policies.
Question 7: Under FERPA, a university uses ACLs to protect student education records. Which ACL rule set best aligns with FERPA requirements?
- Restrict student record system access to authenticated staff systems with documented educational need, blocking all other sources (Correct answer)
- Allow student self-service portals unrestricted access to all student record fields
- Block only off-campus addresses from reaching student data systems
- Permit all campus IP ranges to access the student information system
Correct answer: Restrict student record system access to authenticated staff systems with documented educational need, blocking all other sources
FERPA requires that education records be accessible only to school officials with a legitimate educational interest, which ACLs enforce by restricting network access to authorized systems.
Question 8: In a role-based access control (RBAC) model, what is the primary mechanism used to assign permissions to users?
- Permissions are assigned to roles, and users are assigned to roles (Correct answer)
- Permissions are assigned directly to each user account
- Permissions are determined by the user's department code in Active Directory
- Permissions are inherited from the operating system's default settings
Correct answer: Permissions are assigned to roles, and users are assigned to roles
In RBAC, permissions are attached to roles rather than individual users, and users gain permissions by being assigned to appropriate roles.
Question 9: During a compliance review, auditors require evidence that ACL changes follow a four-eyes principle. Which process satisfies this requirement?
- Logging all ACL changes to a read-only syslog server
- Having one engineer implement all ACL changes independently
- Using automated scripts to apply ACL changes without human intervention
- Requiring peer review and approval in a ticketing system before ACL changes are deployed (Correct answer)
Correct answer: Requiring peer review and approval in a ticketing system before ACL changes are deployed
A four-eyes (dual-control) principle requires a second person to review and approve changes before implementation, typically enforced through a ticketing and approval workflow.
Question 10: In the Diamond Model of intrusion analysis, which element corresponds to the ACL rules that block specific attacker IPs or ports?
- Infrastructure (Correct answer)
- Victim
- Adversary
- Capability
Correct answer: Infrastructure
The Infrastructure element of the Diamond Model refers to IP addresses, domains, and services the adversary uses, which are what IP/port-based ACL rules target.
Question 11: What technique do penetration testers use to bypass ACLs that block standard scanning ports by sending packets with specific TCP flags?
- ARP poisoning to redirect traffic
- SYN flood attacks
- DNS tunneling to exfiltrate data
- ACK scanning or FIN scanning to probe through stateless ACLs (Correct answer)
Correct answer: ACK scanning or FIN scanning to probe through stateless ACLs
ACK and FIN scans exploit stateless ACLs that only filter SYN packets, since these ACLs may permit non-SYN packets that appear to belong to established connections.
Question 12: Which ACL classification operates at Layer 3 and Layer 4 of the OSI model?
- VLAN ACL
- MAC ACL
- Extended ACL (Correct answer)
- Standard ACL
Correct answer: Extended ACL
Extended ACLs examine Layer 3 fields (IP addresses) and Layer 4 fields (TCP/UDP ports and flags) for filtering decisions.
Question 13: What tool do security professionals commonly use to enumerate and visualize ACL-based attack paths in Active Directory?
- BloodHound (Correct answer)
- Nessus
- Metasploit
- Wireshark
Correct answer: BloodHound
BloodHound uses graph analysis to map ACL relationships and Active Directory permissions, revealing privilege escalation paths that attackers could exploit.
Question 14: A user can read a file but cannot modify it. Which type of permission has been applied?
- Execute-only permission
- Write permission with audit
- Read-only permission (Correct answer)
- Deny-all with read exception
Correct answer: Read-only permission
Read-only permission allows a user to view the contents of a file but prevents any modifications.
Question 15: In Access Control Lists, what is the purpose of team-building activities?
- To waste time during work hours
- To strengthen collaboration, trust, and communication (Correct answer)
- To comply with HR requirements
- To identify the weakest team member
Correct answer: To strengthen collaboration, trust, and communication
Team-building activities enhance collaboration, build trust among team members, and improve communication skills.
Question 16: Where should an ACL be applied to ensure security without impacting performance?
- On every router in the network
- Near the source of traffic (Correct answer)
- At the network core
- After the firewall
Correct answer: Near the source of traffic
Applying an ACL near the source of traffic is a best practice for both security and performance. By filtering unwanted traffic as close to its origin as possible, it prevents unnecessary processing and consumption of bandwidth on intermediate network devices. This ensures that only legitimate traffic travels deeper into the network, optimizing overall performance.
Question 17: What is AdminSDHolder in Active Directory?
- A group policy that prevents modification of admin accounts
- A backup domain controller for administrative functions
- A protected container object whose ACL is periodically applied to privileged accounts and groups (Correct answer)
- A service account with domain admin privileges
Correct answer: A protected container object whose ACL is periodically applied to privileged accounts and groups
AdminSDHolder is a special AD container whose ACL is automatically propagated to all protected accounts (such as Domain Admins members) by the SDProp process every 60 minutes.
Question 18: A network defender uses a threat intelligence platform to enrich ACL log data. Which enrichment action provides the most context for a suspicious source IP?
- ARP table lookup on the local switch
- Reverse DNS lookup only
- Ping latency measurement
- WHOIS, ASN, geolocation, and reputation scoring (Correct answer)
Correct answer: WHOIS, ASN, geolocation, and reputation scoring
Combining WHOIS registration data, ASN ownership, geolocation, and threat reputation scoring gives a comprehensive picture of a suspicious IP's risk profile.
Question 19: In attribute-based access control (ABAC), access decisions are made based on which of the following?
- The discretion of the resource owner at time of request
- Attributes of the user, resource, environment, and action being requested (Correct answer)
- Only the user's group membership
- Predefined role assignments stored in a central database
Correct answer: Attributes of the user, resource, environment, and action being requested
ABAC evaluates multiple attributes—user attributes, resource attributes, environmental conditions, and the action—to make fine-grained access decisions.
Question 20: What is the primary purpose of an Identity Provider (IdP) in a federated identity system?
- To authorize access to specific application features
- To store user passwords in an encrypted database
- To authenticate users and assert their identity to service providers (Correct answer)
- To monitor network traffic for unauthorized access attempts
Correct answer: To authenticate users and assert their identity to service providers
An IdP authenticates users and issues identity assertions (tokens or assertions) that other service providers trust.
Question 21: Which ACL-related cloud security concept ensures that service accounts and roles have only the permissions needed for their specific task?
- Need-to-know basis
- Separation of duties
- Defense in depth
- Principle of least privilege (Correct answer)
Correct answer: Principle of least privilege
The principle of least privilege limits ACL grants to the minimum permissions required, reducing the blast radius of a compromised credential.
Question 22: Which statement about Cisco ACL types and their numbered ranges is CORRECT?
- Standard IP ACLs use 1–99; extended use 100–199 (Correct answer)
- Standard ACLs use 200–299; extended use 100–199
- Standard IP ACLs use 100–199; extended use 1–99
- Both standard and extended ACLs share the 1–199 range
Correct answer: Standard IP ACLs use 1–99; extended use 100–199
Cisco standard IP ACLs use numbers 1–99 (expanded: 1300–1999), while extended IP ACLs use 100–199 (expanded: 2000–2699).
Question 23: What is a System Access Control List (SACL) used for in Windows?
- Managing network access to shared resources
- Controlling which users can log into the system
- Defining system-level file permissions for administrators
- Auditing and logging access attempts to secured objects (Correct answer)
Correct answer: Auditing and logging access attempts to secured objects
A SACL specifies the types of access attempts that generate audit log entries, enabling security monitoring and compliance tracking in Windows environments.
Question 24: What is a Discretionary Access Control List (DACL) in Windows security?
- A list of denied users maintained by the domain controller
- A mandatory access control list enforced by the OS kernel
- An ACL that the object owner can modify to control access by users and groups (Correct answer)
- A list of system-defined rules that cannot be modified by users
Correct answer: An ACL that the object owner can modify to control access by users and groups
A DACL is the portion of a Windows security descriptor that the object's owner controls, specifying which trustees have access and the type of access permitted.
Question 25: Which ACL type can filter traffic based on both source and destination IP addresses as well as port numbers?
- Named ACL
- Standard ACL
- Dynamic ACL
- Extended ACL (Correct answer)
Correct answer: Extended ACL
Extended ACLs filter on source/destination IP, protocol, and port numbers, offering much more granular control than standard ACLs.
Question 26: What does running `getfacl -R /data` accomplish on a Linux system?
- Recursively displays the ACL entries for all files and directories under /data (Correct answer)
- Generates a report of files with no ACL entries under /data
- Removes named user ACL entries from /data and its subdirectories
- Resets all ACLs under /data to default values
Correct answer: Recursively displays the ACL entries for all files and directories under /data
The `-R` flag makes `getfacl` operate recursively, displaying the ACL entries for every file and directory within the specified path.
Question 27: When conducting a vulnerability assessment, which tool is most commonly used to automatically audit Cisco ACL configurations for weaknesses?
- Nipper or CIS-CAT for network device configuration analysis (Correct answer)
- Wireshark
- Metasploit Framework
- Burp Suite
Correct answer: Nipper or CIS-CAT for network device configuration analysis
Nipper and CIS-CAT are specialized tools designed to audit router and switch configurations, including ACL rules, against security best practices and known vulnerabilities.
Question 28: What is a fundamental principle of Incident Response & Recovery in Access Control Lists practice?
- Following established standards and best practices (Correct answer)
- Using outdated methods
- Working in isolation without guidance
- Ignoring industry guidelines
Correct answer: Following established standards and best practices
Following established standards and best practices ensures quality and consistency in Incident Response & Recovery.
Question 29: In cloud ACL auditing, which approach is most effective for continuously detecting policy drift from a secure baseline?
- Disabling all wildcard permissions after initial deployment
- Infrastructure-as-Code (IaC) policy scanning combined with runtime CSPM drift detection (Correct answer)
- Quarterly manual review of all IAM policies
- Relying on cloud provider default security recommendations only
Correct answer: Infrastructure-as-Code (IaC) policy scanning combined with runtime CSPM drift detection
Combining IaC scanning (preventive) with CSPM drift detection (detective) provides continuous coverage against policy changes that violate the security baseline.
Question 30: Which of the following scenarios represents a violation of the 'need-to-know' principle?
- An auditor is granted read-only access to financial transaction logs
- A developer is denied access to the HR payroll database
- A sales representative can view customer contracts and also the company's source code repository (Correct answer)
- A network engineer has access only to network device management interfaces
Correct answer: A sales representative can view customer contracts and also the company's source code repository
A sales representative accessing source code has no legitimate business need for it, violating the need-to-know principle.
Question 31: What does the 'WriteDACL' permission allow an attacker to do in Active Directory?
- Create new Organizational Units in the domain
- Modify the DACL of an object to grant themselves additional permissions (Correct answer)
- Read all attributes of an AD object
- Reset the password of any domain user
Correct answer: Modify the DACL of an object to grant themselves additional permissions
WriteDACL allows a principal to modify an object's DACL, enabling an attacker to grant themselves additional rights such as Full Control over that object.
Question 32: What is the role of a code of conduct in Access Control Lists practice?
- It only applies to new employees
- It replaces all laws and regulations
- It is optional and rarely enforced
- It establishes expected behavioral and professional standards (Correct answer)
Correct answer: It establishes expected behavioral and professional standards
A code of conduct sets clear expectations for professional behavior, guiding practitioners in their daily activities and decisions.
Question 33: Time-based ACLs add which dimension to standard ACL filtering?
- User authentication requirements
- Active hours or day-of-week schedules (Correct answer)
- VLAN membership
- Quality of Service markings
Correct answer: Active hours or day-of-week schedules
Time-based ACLs use time-range objects to activate or deactivate permit/deny rules during specified hours or days.
Question 34: An ACL permits traffic from 10.0.0.0/24 but logs show 10.0.0.50 exfiltrating data. Which incident response action addresses the root cause?
- Increase bandwidth on the egress interface
- Block 10.0.0.50 specifically with a deny ACE before the permit statement (Correct answer)
- Expand the ACL to allow all RFC 1918 space
- Remove the entire ACL and rebuild from scratch
Correct answer: Block 10.0.0.50 specifically with a deny ACE before the permit statement
Adding a specific deny ACE for the compromised host before the broad permit statement blocks that host while preserving access for legitimate users.
Question 35: In POSIX-based systems, which command displays the Access Control List entries for a file?
- chown
- getfacl (Correct answer)
- chmod
- ls -l
Correct answer: getfacl
The `getfacl` command displays the ACL entries of files on POSIX-compliant systems.
Question 36: Which Linux command sets an ACL entry granting user 'john' read and write access to a file?
- acl -set john:rw file.txt
- chown john:rw file.txt
- chmod u+rw john file.txt
- setfacl -m u:john:rw file.txt (Correct answer)
Correct answer: setfacl -m u:john:rw file.txt
The `setfacl -m u:john:rw file.txt` command modifies the ACL to grant user john read and write permissions on the specified file.
Question 37: What is the primary function of an Access Control List (ACL)?
- Control network traffic permissions (Correct answer)
- Encrypt data packets
- Monitor server uptime
- Store user credentials
Correct answer: Control network traffic permissions
The primary function of an Access Control List (ACL) is to filter network traffic by defining rules that permit or deny packets based on various criteria. ACLs are configured on network devices like routers and firewalls to control which users or devices can access specific network resources. This mechanism is fundamental for enforcing network security policies and managing traffic flow.
Question 38: When designing cloud ACLs for a PCI DSS-compliant environment, what is the minimum segmentation requirement for the cardholder data environment (CDE)?
- VPN tunnels replace the need for ACL segmentation
- Application-layer authentication alone satisfies PCI segmentation
- Firewall ACLs must isolate the CDE from all other network zones (Correct answer)
- No segmentation required if encryption is used
Correct answer: Firewall ACLs must isolate the CDE from all other network zones
PCI DSS requires firewall-based network segmentation to isolate the CDE from untrusted networks and reduce the scope of compliance requirements.
Question 39: Which cloud security architecture pattern uses ACLs to enforce isolation between different customers sharing the same cloud infrastructure?
- Shared Security Groups across all tenants
- Multi-tenancy isolation via IAM and VPC segmentation (Correct answer)
- Open peering between tenant VPCs
- Single-tenant dedicated hardware only
Correct answer: Multi-tenancy isolation via IAM and VPC segmentation
Cloud providers implement multi-tenancy isolation using IAM policies, VPC boundaries, and network ACLs to ensure one tenant cannot access another's resources.
Question 40: What does the Windows `icacls` command do?
- Lists installed certificates
- Displays and modifies NTFS access control lists on files and directories (Correct answer)
- Configures IP address ACLs on network interfaces
- Manages Internet Connection settings
Correct answer: Displays and modifies NTFS access control lists on files and directories
`icacls` is a Windows command-line tool used to view and modify NTFS discretionary access control lists on files and directories.
Question 41: A cloud ACL rule with a lower rule number is evaluated before a rule with a higher number. What should the last rule in an AWS NACL always be?
- An allow-all rule for outbound traffic
- An allow for administrative SSH traffic
- A log rule for audit purposes
- An explicit deny-all rule (*) (Correct answer)
Correct answer: An explicit deny-all rule (*)
AWS NACLs include an implicit deny-all at rule number *, which blocks any traffic not matched by earlier explicit rules.
Question 42: What is a 'shadow ACL' risk in cloud security architecture?
- Unintended permissions granted through inherited or wildcard ACL rules that bypass intended restrictions (Correct answer)
- ACL logs that are obscured by encryption
- ACL rules copied from on-premises firewalls without review
- Firewall rules that only apply during business hours
Correct answer: Unintended permissions granted through inherited or wildcard ACL rules that bypass intended restrictions
Shadow ACLs occur when overly broad wildcard rules or inherited permissions grant unintended access that bypasses more specific restrictive rules.
Question 43: In Linux extended ACLs, what does a 'default ACL' on a directory do?
- Restricts the file owner's permissions
- Sets a fallback permission when no ACL entry matches
- Defines permissions applied to new files and subdirectories created within that directory (Correct answer)
- Removes all ACL entries from the directory
Correct answer: Defines permissions applied to new files and subdirectories created within that directory
Default ACLs on directories specify the permission template automatically applied to newly created files and subdirectories within that directory.
Question 44: A company needs to allow only HTTPS traffic from the internet to their web server at 172.16.1.10. Which ACL entry achieves this?
- access-list 101 permit tcp any host 172.16.1.10 eq 443 (Correct answer)
- access-list 101 permit ip any host 172.16.1.10
- access-list 101 permit udp any host 172.16.1.10 eq 443
- access-list 101 permit tcp any host 172.16.1.10 eq 80
Correct answer: access-list 101 permit tcp any host 172.16.1.10 eq 443
HTTPS uses TCP port 443, so the correct entry permits TCP traffic from any source to the web server specifically on port 443.
Question 45: During a penetration test, a tester discovers that a router ACL permits inbound Telnet (port 23) from any source. What is the primary security risk?
- Telnet transmits credentials in plaintext, enabling credential interception (Correct answer)
- Telnet uses a non-standard port that is hard to scan
- Telnet is blocked by most firewalls automatically
- Telnet traffic is encrypted but slow
Correct answer: Telnet transmits credentials in plaintext, enabling credential interception
Telnet sends all data, including usernames and passwords, in cleartext, making it trivial for an attacker to capture credentials via packet sniffing.
Question 46: Which Linux file permission octal value grants the owner read and write access while allowing only read access to group and others?
- 700
- 755
- 644 (Correct answer)
- 777
Correct answer: 644
Octal 644 grants the owner read and write (6), and grants group and others read-only access (4), which is the standard for most configuration files.
Question 47: What is the purpose of the 'Protected Users' security group in Active Directory?
- Restricts logon hours for administrative accounts
- Prevents group members from being added to privileged groups
- Applies authentication restrictions to reduce credential theft exposure for sensitive accounts (Correct answer)
- Disables interactive logon for service accounts
Correct answer: Applies authentication restrictions to reduce credential theft exposure for sensitive accounts
Accounts in the Protected Users group cannot use NTLM, DES, or RC4 Kerberos encryption, and credentials are not cached, significantly reducing the attack surface for credential-based attacks.
Question 48: An ACL rule reads: 'deny tcp 192.168.1.0 0.0.0.255 any eq 23'. What traffic does this block?
- HTTP traffic to port 23 on any host
- SSH traffic from 192.168.1.0/24 to any destination
- Telnet traffic originating from the 192.168.1.0/24 subnet (Correct answer)
- All traffic from any source to 192.168.1.0/24
Correct answer: Telnet traffic originating from the 192.168.1.0/24 subnet
Port 23 is Telnet; this rule denies TCP connections from any host in 192.168.1.0/24 to port 23 on any destination.
Question 49: Which POSIX ACL entry type covers users who are not the file owner and do not match any named user or group entry?
- user
- mask
- other (Correct answer)
- group
Correct answer: other
The 'other' ACL entry type defines permissions for users who are neither the owner nor match any named user or group in the ACL.
Question 50: An infrastructure ACL (iACL) is primarily used to:
- Permit only OSPF neighbor adjacencies
- Filter traffic between end-user VLANs
- Manage QoS markings on WAN links
- Protect the network device's control plane from unauthorized access (Correct answer)
Correct answer: Protect the network device's control plane from unauthorized access
Infrastructure ACLs protect router and switch management planes by permitting only legitimate management and routing protocol traffic to the device itself.
Question 51: What is a common Active Directory attack technique that exploits misconfigured ACLs?
- Pass-the-Hash
- DNS poisoning
- ACL abuse using overpermissioned ACEs like WriteDACL or GenericAll to escalate privileges (Correct answer)
- Kerberoasting
Correct answer: ACL abuse using overpermissioned ACEs like WriteDACL or GenericAll to escalate privileges
ACL abuse exploits overly permissive ACEs (such as WriteDACL, GenericWrite, or GenericAll) to escalate privileges or take control of accounts in Active Directory.
Question 52: How does collaboration enhance Threat Intelligence & Analysis in Access Control Lists?
- It slows down the process
- It brings diverse perspectives and improves outcomes (Correct answer)
- It reduces individual accountability
- It creates unnecessary meetings
Correct answer: It brings diverse perspectives and improves outcomes
Collaboration brings together different viewpoints and expertise, leading to better decision-making and outcomes.
Question 53: Which method helps reduce ACL misconfigurations?
- Allow all IPs unrestricted access
- Use standardized rule naming and ordering (Correct answer)
- Avoid documenting ACL changes
- Apply rules randomly
Correct answer: Use standardized rule naming and ordering
Reducing ACL misconfigurations is best achieved by implementing standardized rule naming and ordering conventions. Consistent naming makes rules easier to understand and manage, while a logical ordering (e.g., specific rules before general rules) prevents unintended traffic flow due to the sequential processing of ACLs. This minimizes errors and improves maintainability.
Question 54: What is a fundamental principle of Cloud Security Architecture in Access Control Lists practice?
- Using outdated methods
- Ignoring industry guidelines
- Following established standards and best practices (Correct answer)
- Working in isolation without guidance
Correct answer: Following established standards and best practices
Following established standards and best practices ensures quality and consistency in Cloud Security Architecture.
Question 55: Which ACL feature allows a security team to dynamically permit return traffic for established sessions without writing explicit inbound permit rules?
- Extended ACL with established keyword for TCP (Correct answer)
- Standard ACL with reflexive option
- Dynamic ACL with authentication trigger
- Named ACL with stateful inspection enabled
Correct answer: Extended ACL with established keyword for TCP
The 'established' keyword in an extended ACL permits TCP packets with the ACK or RST bit set, allowing return traffic for sessions initiated outbound without tracking full state.
Question 56: What is the 'mask' entry in a POSIX ACL?
- An inherited permission from the parent directory
- A default permission applied to all new files
- The maximum effective permissions for named users, groups, and other ACL entries (Correct answer)
- A permissions filter applied only to the file owner
Correct answer: The maximum effective permissions for named users, groups, and other ACL entries
The mask entry defines the upper limit of effective permissions that can be granted to named users, named groups, and the owning group in a POSIX ACL.
Question 57: What is ACL-based delegation in Active Directory?
- Delegating Kerberos authentication to a service account
- Granting specific, limited permissions on AD objects to non-admin users for defined administrative tasks (Correct answer)
- Assigning domain admin rights to helpdesk staff
- Transferring FSMO roles between domain controllers
Correct answer: Granting specific, limited permissions on AD objects to non-admin users for defined administrative tasks
ACL-based delegation allows administrators to grant non-privileged users specific rights on particular OUs — such as resetting passwords — without granting full administrative access.
Question 58: Which authentication factor category does a hardware security token (e.g., RSA SecurID) belong to?
- Something you have (Correct answer)
- Something you do
- Something you are
- Something you know
Correct answer: Something you have
A hardware token is a physical device the user possesses, placing it in the 'something you have' authentication category.
Question 59: What Active Directory permission allows a user to create new objects within an Organizational Unit?
- Full Control
- Read
- Create Child Objects (Correct answer)
- Write
Correct answer: Create Child Objects
The 'Create Child Objects' permission grants the right to create new objects such as users, groups, and computers within an OU or container.
Question 60: What is a risk register in Access Control Lists practice?
- An employee directory
- A financial ledger
- A sign-in sheet for safety meetings
- A documented list of identified risks with their analysis and response plans (Correct answer)
Correct answer: A documented list of identified risks with their analysis and response plans
A risk register is a document that records all identified risks, their assessment, and planned responses for tracking and management.
Question 61: What is ACL inheritance in Active Directory?
- Replication of ACLs from one domain to another
- Automatic backup of ACL configurations to a domain controller
- The mechanism by which permissions set on a parent object automatically propagate to child objects (Correct answer)
- Automatic assignment of group memberships to new user accounts
Correct answer: The mechanism by which permissions set on a parent object automatically propagate to child objects
ACL inheritance in Active Directory allows permissions configured on a parent container such as an OU to automatically flow down to its child objects, reducing repetitive administrative configuration.
Question 62: Which technology is most commonly used to implement microsegmentation in modern data centers?
- Hardware-based VLANs and physical firewall appliances
- Intrusion detection systems (IDS) and honeypots
- Software-defined networking (SDN) and virtual firewalls (Correct answer)
- Network address translation (NAT) and proxy servers
Correct answer: Software-defined networking (SDN) and virtual firewalls
Software-defined networking and virtual firewalls enable dynamic, policy-driven microsegmentation that can be applied at the individual workload level without physical hardware changes.
Question 63: Which command is commonly used to configure ACL rules in Cisco devices?
- ping
- show run
- access-list (Correct answer)
- enable secret
Correct answer: access-list
In Cisco IOS, the `access-list` command is the fundamental command used to create and configure Access Control Lists. This command is followed by parameters specifying the ACL number or name, whether it's a permit or deny rule, and the criteria for matching traffic. It is central to defining network traffic filtering policies on Cisco devices.
Question 64: What does NTFS stand for in the context of Windows file system security?
- Native Text File Standard
- Network Transfer File System
- Network Time File Server
- New Technology File System (Correct answer)
Correct answer: New Technology File System
NTFS (New Technology File System) is Microsoft's proprietary file system that supports fine-grained ACL permissions.
Question 65: What is the primary security benefit of implementing single sign-on (SSO)?
- It eliminates the need for any form of user authentication
- It allows users to share credentials safely between departments
- It reduces password fatigue and the risk of weak passwords across multiple systems (Correct answer)
- It replaces the need for multi-factor authentication
Correct answer: It reduces password fatigue and the risk of weak passwords across multiple systems
SSO lets users authenticate once and access multiple systems, reducing password fatigue and the likelihood of password reuse or weak passwords.
Question 66: What is the difference between 'explicit' and 'inherited' NTFS permissions?
- Explicit permissions are set directly on an object; inherited permissions flow down from a parent container (Correct answer)
- Explicit apply to subfolders only; inherited apply to the current folder
- Explicit permissions can only be set by administrators; inherited can be set by any user
- Explicit permissions are temporary; inherited permissions are permanent
Correct answer: Explicit permissions are set directly on an object; inherited permissions flow down from a parent container
Explicit permissions are directly assigned to an object, while inherited permissions are automatically propagated from parent folders in the directory tree.
Question 67: Which cloud ACL model evaluates permissions at the resource level rather than at the identity level?
- Attribute-Based Access Control
- Resource-Based Policy (Correct answer)
- Role-Based Access Control
- Mandatory Access Control
Correct answer: Resource-Based Policy
Resource-based policies are attached directly to cloud resources (e.g., S3 buckets) and define who can access that specific resource.
Question 68: When NTFS 'Allow' and 'Deny' permissions conflict for the same user, which takes precedence?
- Allow always wins
- The administrator decides at login
- The most recently set permission wins
- Deny always wins (Correct answer)
Correct answer: Deny always wins
In NTFS, explicit Deny permissions always override Allow permissions to ensure restrictive security regardless of the order ACEs appear in the list.
Question 69: How does collaboration enhance Cloud Security Architecture in Access Control Lists?
- It slows down the process
- It reduces individual accountability
- It brings diverse perspectives and improves outcomes (Correct answer)
- It creates unnecessary meetings
Correct answer: It brings diverse perspectives and improves outcomes
Collaboration brings together different viewpoints and expertise, leading to better decision-making and outcomes.
Question 70: Which skill is most important for success in Threat Intelligence & Analysis within Access Control Lists?
- Working without any training
- Avoiding feedback
- Resisting change
- Continuous learning and adaptation (Correct answer)
Correct answer: Continuous learning and adaptation
Continuous learning ensures professionals stay current with evolving practices in Threat Intelligence & Analysis.
Question 71: What is the MITRE ATT&CK technique category that ACL-based network segmentation most directly mitigates?
- Lateral Movement via internal network propagation (Correct answer)
- Initial Access via phishing
- Execution via malicious scripts
- Credential Access via password spraying
Correct answer: Lateral Movement via internal network propagation
ACL-based network segmentation limits an attacker's ability to move laterally between network segments after gaining initial access to one host.
Question 72: In AWS, which service acts as the central ACL enforcement point for cross-account resource access?
- AWS Config
- AWS IAM with resource-based policies (Correct answer)
- AWS Shield
- AWS CloudTrail
Correct answer: AWS IAM with resource-based policies
IAM resource-based policies with Principal elements allow cross-account access by explicitly naming trusted accounts or roles.
Question 73: Which of the following is a key characteristic of discretionary access control (DAC)?
- Access is controlled exclusively by a system-wide security policy
- Access levels are determined by government classification labels
- Resource owners can grant or restrict access to their own resources (Correct answer)
- Users cannot modify access permissions under any circumstances
Correct answer: Resource owners can grant or restrict access to their own resources
In DAC, the owner of a resource has discretion over who can access it and can set permissions accordingly.
Question 74: Which command removes a specific numbered ACL from the running configuration?
- remove access-list 100
- delete access-list 100
- no access-list 100 (Correct answer)
- clear access-list 100
Correct answer: no access-list 100
The 'no access-list [number]' command removes the entire numbered ACL from the configuration, deleting all its ACEs at once.
Question 75: In GCP, which construct is equivalent to AWS Security Groups for controlling VM-level network traffic?
- Cloud NAT rules
- Cloud Armor policies
- VPC firewall rules with target tags or service accounts (Correct answer)
- Shared VPC ACLs
Correct answer: VPC firewall rules with target tags or service accounts
GCP VPC firewall rules applied via network tags or service accounts control ingress/egress traffic at the VM instance level.
Question 76: An ACL is configured to permit traffic from 10.0.0.0/8 to a server. Monitoring shows unexpected traffic from 172.16.5.10 reaching the server. What is the most likely cause?
- The server's host firewall is overriding the router ACL
- The router is running asymmetric routing
- The ACL wildcard mask was misconfigured to also match 172.16.0.0/12 (Correct answer)
- VLAN tagging is bypassing the ACL
Correct answer: The ACL wildcard mask was misconfigured to also match 172.16.0.0/12
A misconfigured wildcard mask could unintentionally match IP ranges beyond the intended 10.0.0.0/8, allowing unexpected sources through.
Question 77: Which of the following is a key component of the Zero Trust 'Five Pillars' model developed by the U.S. Department of Defense (DoD)?
- Perimeter Security, Encryption, Logging, Patching, and Backup
- Firewall, IDS, VPN, SIEM, and Endpoint Protection
- Authentication, Authorization, Accounting, Auditing, and Availability
- Identity, Devices, Networks, Applications & Workloads, and Data (Correct answer)
Correct answer: Identity, Devices, Networks, Applications & Workloads, and Data
The DoD Zero Trust Reference Architecture identifies five pillars: Identity, Devices, Networks, Applications & Workloads, and Data, each requiring continuous verification and least-privilege enforcement.
Question 78: What is the importance of staying current with trends in Threat Intelligence & Analysis for Access Control Lists?
- It is not necessary once certified
- It is only required for new professionals
- It ensures practices remain effective and relevant (Correct answer)
- Trends do not affect professional practice
Correct answer: It ensures practices remain effective and relevant
Staying current with industry trends ensures that professional practices remain effective, relevant, and aligned with evolving standards.
Question 79: Which approach best supports quality outcomes in Cloud Security Architecture for Access Control Lists?
- Rushing through tasks
- Systematic application of evidence-based methods (Correct answer)
- Avoiding quality checks
- Relying solely on intuition
Correct answer: Systematic application of evidence-based methods
Evidence-based methods provide a reliable foundation for achieving consistent, high-quality outcomes.
Question 80: Which IAM control is specifically designed to verify that user access rights remain appropriate over time?
- Single sign-on
- Access certification (user access review) (Correct answer)
- Multi-factor authentication
- Password complexity policy
Correct answer: Access certification (user access review)
Access certification is a periodic review process where managers verify that users still need and are authorized for their current access rights.
Question 81: Which concept in zero-trust architecture directly replaces the traditional 'trust but verify' perimeter model?
- Granting access based solely on IP address allow-lists
- Never trust, always verify—regardless of network location (Correct answer)
- Implicit trust within internal network segments
- Trusting all traffic that originates from within the corporate VPN
Correct answer: Never trust, always verify—regardless of network location
Zero trust mandates that no user or device is trusted by default, even inside the network perimeter—every access request must be verified.
Question 82: An analyst wants to detect ACL rule evasion using fragmented IP packets. Which characteristic of fragmented traffic makes it a threat intelligence concern?
- IP fragmentation disables encryption
- Fragmented traffic always indicates DDoS
- Fragments may bypass port-based ACL rules if only the first fragment contains port information (Correct answer)
- Fragmented packets always use UDP
Correct answer: Fragments may bypass port-based ACL rules if only the first fragment contains port information
Traditional ACLs that match on port numbers may only inspect the first fragment; subsequent fragments lack layer-4 headers, potentially bypassing ACL rules.
Question 83: Under the CIS Benchmarks for network devices, what is the recommended treatment of the ACL 'permit ip any any' rule?
- It should never appear in a production ACL on external-facing interfaces (Correct answer)
- It is acceptable if followed by more restrictive rules
- It is recommended for internal core switches
- It should be placed at the top for management traffic
Correct answer: It should never appear in a production ACL on external-facing interfaces
CIS Benchmarks prohibit 'permit ip any any' on external-facing interfaces as it negates all other ACL controls and violates least-privilege.
Question 84: What does the sticky bit do when set on a Linux directory?
- Allows only the file owner or root to delete or rename files within the directory (Correct answer)
- Grants execute permission to all users
- Makes the directory contents invisible to non-owners
- Prevents all users from writing to the directory
Correct answer: Allows only the file owner or root to delete or rename files within the directory
The sticky bit on a Linux directory ensures only the file owner or root can delete or rename files within it, even if others have write permission on the directory.
Question 85: An engineer is implementing ACLs on a Cisco router and notices the implicit deny at the end. What action should be taken to meet logging compliance requirements for denied traffic?
- Remove the implicit deny and add a custom permit rule
- Add an explicit 'deny any any log' rule before the implicit deny (Correct answer)
- Apply the ACL outbound only to avoid log clutter
- Enable SNMP traps instead of ACL logging
Correct answer: Add an explicit 'deny any any log' rule before the implicit deny
The implicit deny does not generate log entries; adding an explicit 'deny any any log' statement captures denied traffic for compliance logging.
Question 86: A wildcard mask of 0.0.255.255 in a Cisco ACL matches which address range when paired with the network address 10.10.0.0?
- All IPv4 addresses
- All addresses from 10.10.0.0 through 10.10.255.255 (Correct answer)
- All addresses from 10.0.0.0 through 10.255.255.255
- Only the host 10.10.0.0
Correct answer: All addresses from 10.10.0.0 through 10.10.255.255
A wildcard mask of 0.0.255.255 means the last two octets are variable, so paired with 10.10.0.0 it matches 10.10.0.0 through 10.10.255.255 (a /16 block).
Access Control Lists (ACL) Practice Test
A comprehensive practice test covering Access Control Lists across networking, operating systems, identity management, cloud security, and compliance domains. Tests knowledge of ACL configuration, implementation, and management in real-world enterprise environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds