05.03.2013 Views

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Page<br />

8-32<br />

Page<br />

8-33<br />

8-43<br />

4. If you do not want a user or group to gain access to a particular folder or file,<br />

should you deny access permissions to that folder or file?<br />

You should assign permissions to the folder or file rather than deny permission to access the<br />

folder or file. Denying permissions should be an exception, not common practice.<br />

Case Scenario Exercise<br />

1. Will users in the Part Time And Contractors group be able to open the files protected<br />

by the confidentiality agreement?<br />

No. The Deny Full Control permission will prevent users from being able to access the file.<br />

2. Even if users of the Part Time And Contractors groups cannot access the file, there<br />

is a risk that they will delete the file. Why?<br />

Full Control includes the Delete Subfolders And Files special permission for POSIX compliance.<br />

This special permission allows a user to delete files in the root of a folder to which the user has<br />

been assigned Full Control permission. This permission overrides the file permissions.<br />

3. How could you solve this problem by changing permissions on the Client<br />

Accounts folder?<br />

Allow users all of the individual permissions, and then deny users the Delete Subfolders And<br />

Files special permission.<br />

4. What would have been a better way to approach this problem from the beginning?<br />

It is better to not use Deny permissions unless absolutely necessary. The simplest and most<br />

secure way to approach this problem would be to put the files that are protected by a confidentiality<br />

agreement into a separate folder from the Client Accounts folder. You could then grant<br />

permissions on the separate folder only to users that need permissions.<br />

Troubleshooting Lab<br />

Questions and Answers<br />

1. Based on the information in tables that your boss gave you, what are David’s<br />

effective permissions on the Brochures folder?<br />

To determine David’s effective permissions, you must combine all the permissions that have<br />

been assigned. Thus, David’s effective permissions on the Brochures folder are Read & Execute,<br />

List Folder Contents, and Read.<br />

2. Your boss stops by and says, “Whoops, here is the other table I meant to give<br />

you.” The table shows the permissions assigned to the Accounting group for the<br />

Brochures folder. A user named Yvette is a member the Sales, Marketing, and<br />

Accounting groups.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!