05.03.2013 Views

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

8-36 Chapter 8 Securing Resources with NTFS Permissions<br />

<strong>Exam</strong> Highlights<br />

Key Points<br />

Key Terms<br />

Before taking the exam, review the key points and terms that are presented in this<br />

chapter. You need to know this information.<br />

■ To calculate effective NTFS permissions, first combine all allow permissions from<br />

all sources. Next, determine any deny permissions the user has. Deny permissions<br />

override allow permissions. The result is the user’s effective permissions for the<br />

resource.<br />

■ When you grant permissions, grant users the minimum permissions that they need<br />

to get their jobs done. This is referred to as the principle of least privilege.<br />

■ When you move files or folders within an NTFS volume, permissions that have<br />

been directly assigned to the file or folder carry over to the new location. In all<br />

other cases of moving and copying, existing permissions are lost, and the object<br />

will inherit permissions from the new parent. When moving to a FAT volume, permissions<br />

are lost entirely.<br />

access control entry (ACE) A specific entry on the ACL that grants or denies a user<br />

or group access to a resource.<br />

access control list (ACL) A list of all user accounts and groups that have been<br />

assigned permissions for the file or folder, as well as the permissions that they<br />

have been assigned.<br />

effective permissions The permissions level that a user actually has, taking all permission<br />

sources into account.<br />

NTFS permissions Assignments that specify which users and groups can access files<br />

and folders and what they can do with the contents of the files or folders. NTFS<br />

permissions are available only on NTFS volumes.<br />

owner The user who created a file, folder, or printer.<br />

permissions inheritance The process of a file or folder receiving permissions<br />

based on the permissions assigned to the object’s parent folder.<br />

Traverse Folder A permission that allows or denies moving through folders to<br />

access other files or folders, even when the user has no permissions for the traversed<br />

folder (the folder that the user is moving through).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!