โ† All CSA Flashcard Decks

Access Control Rules (ACLs) Flashcards

7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control Rules (ACLs) flashcards as text
  1. Which ACL operation type controls whether a user can see a specific field on a form or list?

    Answer: read

    The 'read' operation in an ACL determines whether a user can view a field's value on forms and lists.

  2. What happens when multiple ACLs match the same record and operation in ServiceNow?

    Answer: Access is granted if any one matching ACL passes

    ServiceNow grants access if any one of the matching ACLs evaluates to true, following an OR logic across multiple matching rules.

  3. In an ACL script condition, which variable refers to the current record being evaluated?

    Answer: current

    The 'current' variable in ACL scripts refers to the GlideRecord of the record currently being evaluated for access.

  4. Which ACL type would you configure to restrict REST API access to a specific ServiceNow table?

    Answer: Table ACL

    A Table-level ACL with the appropriate HTTP operation (GET, POST, etc.) controls REST API access to an entire table.

  5. What is the effect of setting an ACL's 'Requires role' field to a role that no active user possesses?

    Answer: All users are denied access controlled by that ACL

    If a required role is set but no user has it, all non-admin users will be denied the access controlled by that ACL.

  6. Which ServiceNow feature allows you to test ACL rules without actually changing user permissions?

    Answer: Impersonation

    Impersonation allows admins to log in as another user to test exactly what that user can and cannot access under current ACL rules.

  7. What does the 'Advanced' checkbox on an ACL rule enable?

    Answer: A custom script condition field for complex logic

    Checking 'Advanced' on an ACL reveals the script condition field, allowing administrators to write custom JavaScript logic for access evaluation.