Access Control Lists (ACL) Practice Test — Questions and Answers
Question 1: What is the purpose of the 'Protected Users' security group in Active Directory?
- Restricts logon hours for administrative accounts
- Prevents group members from being added to privileged groups
- Applies authentication restrictions to reduce credential theft exposure for sensitive accounts (Correct answer)
- Disables interactive logon for service accounts
Correct answer: Applies authentication restrictions to reduce credential theft exposure for sensitive accounts
Accounts in the Protected Users group cannot use NTLM, DES, or RC4 Kerberos encryption, and credentials are not cached, significantly reducing the attack surface for credential-based attacks.
Question 2: When designing cloud ACLs for a PCI DSS-compliant environment, what is the minimum segmentation requirement for the cardholder data environment (CDE)?
- VPN tunnels replace the need for ACL segmentation
- No segmentation required if encryption is used
- Firewall ACLs must isolate the CDE from all other network zones (Correct answer)
- Application-layer authentication alone satisfies PCI segmentation
Correct answer: Firewall ACLs must isolate the CDE from all other network zones
PCI DSS requires firewall-based network segmentation to isolate the CDE from untrusted networks and reduce the scope of compliance requirements.
Question 3: What does a zero hit count on an ACL deny rule likely indicate during troubleshooting?
- The rule is blocking all traffic effectively
- Traffic matching that rule has not been seen, or the ACL is not applied correctly (Correct answer)
- The rule was recently cleared and counts are resetting
- The device's TCAM is full and ignoring the rule
Correct answer: Traffic matching that rule has not been seen, or the ACL is not applied correctly
A zero hit count means either no traffic matching that ACE has arrived, or the ACL is not applied to the correct interface or direction.
Question 4: A HIPAA-covered entity is configuring ACLs. Which data characteristic determines how strictly access must be controlled under HIPAA?
- Whether the data is stored in the cloud
- Whether the data originates from a mobile device
- Whether the data is encrypted at rest
- Whether the data constitutes electronic Protected Health Information (ePHI) (Correct answer)
Correct answer: Whether the data constitutes electronic Protected Health Information (ePHI)
HIPAA's Security Rule requires access controls specifically for systems containing electronic Protected Health Information (ePHI).
Question 5: Which term describes the practice of granting users only the minimum access rights needed to perform their job functions?
- Zero trust
- Need-to-know
- Role segmentation
- Least privilege (Correct answer)
Correct answer: Least privilege
The principle of least privilege limits user access to only what is required for their specific role, reducing the attack surface.
Question 6: In Linux extended ACLs, what does a 'default ACL' on a directory do?
- Removes all ACL entries from the directory
- Sets a fallback permission when no ACL entry matches
- Restricts the file owner's permissions
- Defines permissions applied to new files and subdirectories created within that directory (Correct answer)
Correct answer: Defines permissions applied to new files and subdirectories created within that directory
Default ACLs on directories specify the permission template automatically applied to newly created files and subdirectories within that directory.
Question 7: Which ACL-related cloud security concept ensures that service accounts and roles have only the permissions needed for their specific task?
- Need-to-know basis
- Defense in depth
- Separation of duties
- Principle of least privilege (Correct answer)
Correct answer: Principle of least privilege
The principle of least privilege limits ACL grants to the minimum permissions required, reducing the blast radius of a compromised credential.
Question 8: Where should an ACL be applied to ensure security without impacting performance?
- At the network core
- Near the source of traffic (Correct answer)
- After the firewall
- On every router in the network
Correct answer: Near the source of traffic
Applying an ACL near the source of traffic is a best practice for both security and performance. By filtering unwanted traffic as close to its origin as possible, it prevents unnecessary processing and consumption of bandwidth on intermediate network devices. This ensures that only legitimate traffic travels deeper into the network, optimizing overall performance.
Question 9: Which metric derived from ACL logs is most useful for establishing a traffic baseline for anomaly detection?
- Average permit and deny hit rates per ACE over a defined time period (Correct answer)
- The number of interfaces with ACLs applied in both directions
- The total number of ACL rules configured on all interfaces
- The age of the oldest ACL configuration on the device
Correct answer: Average permit and deny hit rates per ACE over a defined time period
Tracking average hit rates per ACE over time creates a baseline that allows detection of anomalous spikes or drops indicating attacks or misconfigurations.
Question 10: In NTFS, what does 'propagation of permissions' refer to?
- Automatic application of parent folder permissions to child objects via inheritance (Correct answer)
- Manually copying permissions from one object to another
- Distributing permissions across multiple network shares
- Synchronizing permissions between domain controllers
Correct answer: Automatic application of parent folder permissions to child objects via inheritance
Permission propagation in NTFS is the automatic inheritance mechanism by which a parent folder's permissions cascade down to its child files and subfolders.
Question 11: What is the significance of ACL sequence numbers in named ACLs on Cisco IOS?
- They allow specific ACEs to be inserted between existing entries or deleted individually (Correct answer)
- They limit how many packets each ACE can match
- They define the time-to-live for dynamic ACL entries
- They determine the priority of the ACL over other ACLs on the same interface
Correct answer: They allow specific ACEs to be inserted between existing entries or deleted individually
Sequence numbers in named ACLs allow administrators to insert new ACEs at a specific position (e.g., sequence 15 between 10 and 20) or delete a specific ACE by its sequence number.
Question 12: In OAuth 2.0, what is the role of an 'access token'?
- It replaces the user's password for all future authentications
- It grants a third-party application limited access to a user's resources without exposing credentials (Correct answer)
- It encrypts communication between the client and the authorization server
- It permanently identifies a user to all services they visit
Correct answer: It grants a third-party application limited access to a user's resources without exposing credentials
An OAuth 2.0 access token authorizes a client application to access specific resources on behalf of a user without sharing the user's credentials.
Question 13: Which IAM control is specifically designed to verify that user access rights remain appropriate over time?
- Password complexity policy
- Single sign-on
- Access certification (user access review) (Correct answer)
- Multi-factor authentication
Correct answer: Access certification (user access review)
Access certification is a periodic review process where managers verify that users still need and are authorized for their current access rights.
Question 14: Which cloud security architecture pattern uses ACLs to enforce isolation between different customers sharing the same cloud infrastructure?
- Multi-tenancy isolation via IAM and VPC segmentation (Correct answer)
- Open peering between tenant VPCs
- Single-tenant dedicated hardware only
- Shared Security Groups across all tenants
Correct answer: Multi-tenancy isolation via IAM and VPC segmentation
Cloud providers implement multi-tenancy isolation using IAM policies, VPC boundaries, and network ACLs to ensure one tenant cannot access another's resources.
Question 15: A 'permit ip any any' rule exists in an ACL but traffic is still being blocked. What is the most likely cause?
- The interface has no ACL applied
- A more specific deny entry appears before the permit statement in the ACL (Correct answer)
- The router's CPU is overloaded
- The 'ip any any' syntax is invalid and ignored
Correct answer: A more specific deny entry appears before the permit statement in the ACL
Because ACLs process entries top-down and stop at the first match, a deny statement appearing before 'permit ip any any' will catch matching traffic before the permit is ever evaluated.
Question 16: What does the Windows `icacls` command do?
- Manages Internet Connection settings
- Configures IP address ACLs on network interfaces
- Lists installed certificates
- Displays and modifies NTFS access control lists on files and directories (Correct answer)
Correct answer: Displays and modifies NTFS access control lists on files and directories
`icacls` is a Windows command-line tool used to view and modify NTFS discretionary access control lists on files and directories.
Question 17: What is the difference between 'explicit' and 'inherited' NTFS permissions?
- Explicit permissions are set directly on an object; inherited permissions flow down from a parent container (Correct answer)
- Explicit permissions are temporary; inherited permissions are permanent
- Explicit permissions can only be set by administrators; inherited can be set by any user
- Explicit apply to subfolders only; inherited apply to the current folder
Correct answer: Explicit permissions are set directly on an object; inherited permissions flow down from a parent container
Explicit permissions are directly assigned to an object, while inherited permissions are automatically propagated from parent folders in the directory tree.
Question 18: What is the primary purpose of an Identity Provider (IdP) in a federated identity system?
- To authenticate users and assert their identity to service providers (Correct answer)
- To store user passwords in an encrypted database
- To monitor network traffic for unauthorized access attempts
- To authorize access to specific application features
Correct answer: To authenticate users and assert their identity to service providers
An IdP authenticates users and issues identity assertions (tokens or assertions) that other service providers trust.
Question 19: Which Windows interface provides a GUI to manage NTFS file and folder permissions?
- File Explorer Properties > Security tab (Correct answer)
- Task Manager
- Registry Editor
- Device Manager
Correct answer: File Explorer Properties > Security tab
The Security tab in a file or folder's Properties dialog in Windows File Explorer provides a graphical interface for managing NTFS ACL permissions.
Question 20: How does collaboration enhance Cloud Security Architecture in Access Control Lists?
- It slows down the process
- It brings diverse perspectives and improves outcomes (Correct answer)
- It creates unnecessary meetings
- It reduces individual accountability
Correct answer: It brings diverse perspectives and improves outcomes
Collaboration brings together different viewpoints and expertise, leading to better decision-making and outcomes.
Question 21: What does the term 'provisioning' refer to in identity management?
- The process of creating and assigning user accounts and access rights (Correct answer)
- Revoking access when an employee leaves
- Auditing user activity logs for compliance
- Encrypting user credentials in a directory
Correct answer: The process of creating and assigning user accounts and access rights
Provisioning is the process of setting up user identities and granting them the appropriate access rights to systems and resources.
Question 22: An encryption policy mandates 'authenticated encryption.' What additional guarantee does this provide over encryption-only modes?
- Automatic key rotation
- Faster throughput
- Larger key sizes
- Integrity and authenticity verification alongside confidentiality (Correct answer)
Correct answer: Integrity and authenticity verification alongside confidentiality
Authenticated encryption (e.g., AES-GCM or ChaCha20-Poly1305) simultaneously provides confidentiality, integrity, and authenticity, detecting any ciphertext tampering.
Question 23: When configuring an extended ACL on a Cisco router, where is it best practice to place it?
- As close to the destination as possible
- As close to the source as possible (Correct answer)
- At the core layer of the network hierarchy
- On the default gateway of the destination network
Correct answer: As close to the source as possible
Extended ACLs should be placed close to the source to block unwanted traffic early and avoid consuming unnecessary bandwidth.
Question 24: What is the primary purpose of configuring ACL rules?
- Increase network bandwidth
- Store user credentials
- Control and restrict network traffic (Correct answer)
- Allow unrestricted access
Correct answer: Control and restrict network traffic
The primary purpose of configuring ACL rules is to control the flow of network traffic. ACLs act as filters, allowing administrators to permit or deny packets based on various criteria like source/destination IP, port numbers, or protocols. This restriction is crucial for enforcing security policies and managing network resource access.
Question 25: Which Linux ACL feature allows setting different permissions for multiple individual users on the same file?
- chmod with multiple flags
- Named user ACL entries configured via setfacl (Correct answer)
- Umask configuration in the shell profile
- Group ownership changes with chgrp
Correct answer: Named user ACL entries configured via setfacl
Named user ACL entries, set with `setfacl -m u:username:permissions`, allow distinct permissions to be assigned to multiple individual users on a single file beyond the standard owner/group/others model.
Question 26: Under HIPAA, which ACL configuration best protects electronic Protected Health Information (ePHI) at the network perimeter?
- Allow all inbound traffic and log only outbound
- Permit all internal traffic and block only known malicious IPs
- Deny all traffic by default and permit only specific authorized connections to ePHI systems (Correct answer)
- Use MAC-based filtering on switches to control ePHI access
Correct answer: Deny all traffic by default and permit only specific authorized connections to ePHI systems
HIPAA requires a 'deny all, permit by exception' ACL posture to ensure only explicitly authorized traffic can reach systems holding ePHI.
Question 27: How does a stateless ACL differ from a stateful firewall ACL?
- Stateless ACLs evaluate each packet independently without tracking session state (Correct answer)
- Stateless ACLs track TCP connection state; stateful ACLs do not
- Stateless ACLs are always applied outbound
- Stateless ACLs can only be used on Layer 2 switches
Correct answer: Stateless ACLs evaluate each packet independently without tracking session state
Traditional router ACLs are stateless — each packet is evaluated independently with no memory of prior packets in a session.
Question 28: Which term describes ACLs that are automatically generated by Cisco IOS to support features like NAT or GRE tunnels?
- Dynamic ACLs
- Infrastructure ACLs
- Implicit system-generated ACLs (Correct answer)
- Reflexive ACLs
Correct answer: Implicit system-generated ACLs
IOS automatically creates implicit system-generated ACL entries to support internal features such as NAT translations and tunnel encapsulation.
Question 29: What is the foundation of professional ethics in Access Control Lists?
- Maximizing profit at all costs
- Following only verbal instructions
- Acting with integrity, honesty, and accountability (Correct answer)
- Avoiding difficult decisions
Correct answer: Acting with integrity, honesty, and accountability
Professional ethics are built on principles of integrity, honesty, and accountability, which guide practitioners in making responsible decisions.
Question 30: Which threat intelligence feed format is most commonly used to share ACL-relevant indicators such as malicious IP ranges and domain lists in a machine-readable way?
- SNMP trap
- CSV flat file
- Syslog CEF
- STIX/TAXII (Correct answer)
Correct answer: STIX/TAXII
STIX defines the structured format for threat indicators, and TAXII is the transport protocol used to share them automatically.
Access Control Lists (ACL) Practice Test
A comprehensive practice test covering Access Control Lists across networking, operating systems, identity management, cloud security, and compliance domains. Tests knowledge of ACL configuration, implementation, and management in real-world enterprise environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds