Access Control Rules (ACLs) Flashcards
7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Access Control Rules (ACLs) flashcards as text
Which of the following ACL operations would you use to prevent users from deleting records in the Incident table?
Answer: delete
The 'delete' operation ACL controls whether users can remove records from a table.
How does ACL inheritance work when a child table extends a parent table in ServiceNow?
Answer: Child tables inherit all ACLs from the parent table automatically
In ServiceNow, ACLs defined on a parent table are automatically inherited by all child (extended) tables unless overridden.
What is the correct order of ACL evaluation specificity from most specific to least specific?
Answer: Field → Table → * (global)
ServiceNow evaluates ACLs from most specific (field-level) to least specific (table-level to global wildcard), applying the most specific matching rule.
An ACL has a role condition set to 'itil' and a script that checks if the record's state equals 1. When does access get granted?
Answer: When the user has the itil role AND the script returns true
All conditions in an ACL (roles, conditions, and scripts) must pass simultaneously — they are evaluated with AND logic, not OR.
Which system property controls whether ServiceNow logs ACL denials for debugging purposes?
Answer: glide.security.log.denials
The system property 'glide.security.log.denials' enables logging of ACL denial events, which appear in the system log for troubleshooting.
What is the purpose of the 'contains' condition type in an ACL's condition builder?
Answer: Verifies that a list field includes a particular choice value
The 'contains' condition in ACL builders is used to check whether a list-type field (like a role list or category list) includes a specific value.
Which role is required by default to create or modify ACL rules in a production ServiceNow instance?
Answer: security_admin
The 'security_admin' role is required to create or modify ACL rules, and must be explicitly elevated even for users with the admin role.