โ† All CSA Flashcard Decks

Access Control Rules (ACLs) Flashcards

6 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Access Control Rules (ACLs) flashcards as text
  1. A user has the 'itil' role. There are two 'write' ACLs for the Incident table: 1. An ACL for `incident.short_description` that requires the 'incident_manager' role. 2. An ACL for `incident.*` that requires the 'itil' role. Which statement correctly describes the user's ability to write to the 'short_description' field?

    Answer: The user cannot write to the field because the more specific `incident.short_description` ACL restricts access.

    ServiceNow evaluates ACLs from the most specific to the most general. The rule for `incident.short_description` is more specific than the wildcard `incident.*` rule. Since the user lacks the 'incident_manager' role, the specific rule denies access, and the broader rule is not evaluated for this particular field.

  2. An administrator needs to prevent a specific role from editing incidents that are in a 'Closed' state. The ACL should only be evaluated for existing records. Which ACL configuration would achieve this?

    Answer: Operation: `write`, Condition: State is not Closed

    A 'write' operation ACL controls the ability to update existing records. By setting a condition 'State is not Closed', the rule will only grant write access to records that are not in the 'Closed' state, effectively making them read-only when closed.

  3. What is the primary function of an Access Control List (ACL) in the ServiceNow platform?

    Answer: To secure records and fields against unauthorized create, read, write, and delete operations.

    The core purpose of ACLs is to act as security rules that restrict access to data. They define what data users can Create, Read, Write, and Delete (CRUD) in ServiceNow tables and fields, ensuring data confidentiality and integrity.

  4. Which of the following BEST describes the purpose of a wildcard ACL rule, such as `cmdb_ci.*`?

    Answer: It provides a baseline security rule for all fields on a table that do not have their own specific field-level ACLs.

    A wildcard ACL (`table.*`) serves as a default security rule for all fields on that table. However, if a more specific ACL exists for a particular field (e.g., `cmdb_ci.name`), the specific ACL takes precedence for that field, and the wildcard ACL is not evaluated for that operation.

  5. An administrator is writing an ACL script to check if a user belongs to the 'cab_delegates' group. Which GlideSystem (gs) method should be used in the script to determine the current user's group membership?

    Answer: gs.getUser().isMemberOf('cab_delegates')

    The `gs.getUser()` method returns the user object of the currently logged-in user. This user object has the `isMemberOf()` method, which can be used to check for membership in a specific group. `gs.hasRole()` checks for roles, not groups.

  6. For a user to have read access to a specific field on a record, what combination of ACLs must be passed?

    Answer: The user must pass both a table-level 'read' ACL AND a field-level 'read' ACL.

    ServiceNow's security model requires users to pass access checks at both the record/table level and the field level. A user must have permission to read the record (from a table-level ACL like `incident`) and also have permission to read the specific field (from a field-level ACL like `incident.short_description` or `incident.*`).