05.03.2013 Views

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

8-12 Chapter 8 Securing Resources with NTFS Permissions<br />

!<br />

Table 8-5 Special Permissions<br />

Permission Description<br />

Create Folders/<br />

Append Data<br />

Create Folders allows or denies the creation of folders within the folder.<br />

Create Folders applies only to folders.<br />

Append Data allows or denies making changes to the end of the file, but<br />

not changing, deleting, or overwriting existing data. Append Data applies to<br />

files only.<br />

Write Attributes Write Attributes allows or denies the changing of the attributes of a file or<br />

folder. These attributes are defined by NTFS.<br />

Write Extended<br />

Attributes<br />

Delete Subfolders<br />

And Files<br />

Write Extended Attributes allows or denies the changing of the extended<br />

attributes of a file or a folder. These attributes are defined by programs.<br />

Delete Subfolders And Files allows or denies the deletion of subfolders or<br />

files within a folder, even if the Delete permission has not been granted on<br />

the particular subfolder or file.<br />

Delete Delete allows or denies the deletion of a file or folder. A user can delete a<br />

file or folder even without having the Delete permission granted on that file<br />

or folder, if the Delete Subfolder And Files permission has been granted to<br />

the user on the parent folder.<br />

Read Permissions Read Permissions allows or denies the reading of the permissions assigned<br />

to the file or folder.<br />

Change Permissions<br />

Change Permissions allows or denies the changing of the permissions<br />

assigned to the file or folder. You can give other administrators and users<br />

the ability to change permissions for a file or folder without giving them the<br />

Full Control permission over the file or folder. In this way, the administrator<br />

or user cannot delete or write to the file or folder, but can assign permissions<br />

to the file or folder.<br />

Take Ownership Take Ownership allows or denies taking ownership of the file or folder. The<br />

owner of a file can always change permissions on a file or folder, regardless<br />

of the permissions set to protect the file or folder.<br />

Synchronize Synchronize allows or denies different threads in a multithreaded program<br />

to synchronize with one another. A multithreaded program performs multiple<br />

actions simultaneously by using both processors in a dual-processor<br />

computer. This permission is not assigned to users, but instead applies only<br />

to multithreaded programs.<br />

<strong>Exam</strong> Tip When you grant permissions, grant users the minimum permissions that they<br />

need to get their job done. This is referred to as the principle of least privilege.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!