Security+ SY0-701 · Hands-on Lab

Restrict a folder with NTFS permissions & disable inheritance

Lock down a sensitive directory on a file server so only the right group can reach it, then stop permissions from flowing down from the parent. Work in the simulated security console on the left; the checklist tracks you automatically.

2.5.2 Access control · ACL / Permissions 4.6.2 Permission assignments 4.6.8.2 Discretionary access control

Scenario

You administer the file server VAULT-FS01 at Meridian Freight Co. The internal audit team keeps quarterly working papers in E:\AuditWorkpapers. Right now the folder simply inherits everything from the drive root, so far more people can open it than should.

Your job: give the security group MERIDIAN\Audit-Leads exclusive control of the folder, and cut off the inherited access so general Users can no longer reach it.

AuditWorkpapers — Properties
Object name:
E:\AuditWorkpapers

Group or user names

Inheritance: on
    Permissions for Select an entry
    PermissionAllowDeny
    Select an entry above, or add the audit group, to view its permissions.