050-696 · Question #154
Click the Exhibit button to begin. The user object DCoughanour is a member of the Techs group. This group has been assigned Read and File Scan file system rights to the KNOWLEDGE folder. EDIT is a…
The correct answer is G. Read, Write, Modify, File Scan, Access Control. In Novell NetWare, an Inherited Rights Filter (IRF) blocks rights inherited from parent directories, but explicit trustee assignments made directly on a directory bypass the IRF entirely.
Question
Exhibit
Options
- ASupervisor
- BRead, File Scan
- CCreate, Erase
- DRead, Modify, File Scan
- ERead, Write, File Scan
- FRead, Write, Modify, Access Control
- GRead, Write, Modify, File Scan, Access Control
- HRead, Write, Create, Erase, Modify, File Scan, Access Control
- IThis object has no rights to the EDIT directory.
How the community answered
(20 responses)- A5% (1)
- C10% (2)
- G85% (17)
Why each option
In Novell NetWare, an Inherited Rights Filter (IRF) blocks rights inherited from parent directories, but explicit trustee assignments made directly on a directory bypass the IRF entirely.
Supervisor right is not assigned to DCoughanour or the Techs group at any level in this scenario.
Read and File Scan represents only the inherited portion that passes through the IRF, ignoring DCoughanour's explicit trustee assignment on EDIT.
Create and Erase are not present in any trustee assignment or inherited rights in this scenario.
This omits Write and Access Control rights that are part of DCoughanour's explicit assignment on EDIT.
This omits Modify and Access Control from the explicit trustee assignment DCoughanour holds on EDIT.
This lists only the explicit trustee assignment rights but fails to include File Scan, which passes the IRF as an inherited right.
The Techs group trustee assignment of Read and File Scan flows down from KNOWLEDGE to EDIT, but the IRF on EDIT blocks all except Supervisor and File Scan, leaving only File Scan as the inherited right. DCoughanour's explicit trustee assignment on EDIT (Read, Write, Modify, Access Control) is never filtered by an IRF. Combining these yields effective rights of Read, Write, Modify, File Scan, and Access Control.
Create and Erase are not assigned anywhere in the described rights chain and cannot be part of effective rights.
DCoughanour has an explicit trustee assignment on EDIT, which always grants rights regardless of the IRF.
Concept tested: NetWare IRF interaction with explicit trustee assignments
Source: https://www.novell.com/documentation/nw65/index.html
Topics
Community Discussion
6The answer is G, Read, Write, Modify, File Scan, Access Control, because an IRF only blocks inherited rights, it has zero effect on explicit trustee assignments. DCoughanour's direct assignment of Read, Write, Modify, and Access Control to EDIT survives the IRF untouched, and File Scan still flows down through the IRF from the Techs group inheritance since the IRF allows it, so you add that in and get the full G set.
Solid breakdown, though worth noting that File Scan flowing through the IRF only matters if the Techs group actually has an effective File Scan right at that point in the tree, so a card worth making is the two-step check: IRF filter first, then verify the source trustee assignment exists.
The IRF blocks everything except Supervisor and File Scan, and since DCoughanour does not hold the Supervisor right, his explicit assignment of Read, Write, Modify, and Access Control gets wiped out at the EDIT directory boundary, leaving him with only File Scan, but File Scan alone does not grant him any actual access to the contents of the directory. I keep coming back to I because without even Read rights surviving in a usable way, he effectively has no working access to those files.
Ingrid, the IRF only filters inherited rights, not explicit trustee assignments, so DCoughanour's direct assignment of Read, Write, Modify, and Access Control at the EDIT directory survives the filter completely intact, which is exactly why G is correct.
Okay so I spent a solid hour on this one and I keep landing on C, Create and Erase, and here is my clock-on-the-wall reasoning. The IRF on EDIT blocks everything except Supervisor and File Scan, which means the inherited Read and File Scan from Techs get gutted down to just File Scan, but then the explicit trustee assignment for DCoughanour kicks in and I think the IRF filters that too, leaving only the rights that survive the IRF mask, and Create and Erase are what punch through from his explicit set after the mask interaction. Flag this one if you are under time pressure because the IRF layering is a trap and you will second-guess yourself, but if you have a minute to work through it the IRF always wins against inherited rights and the explicit assignment gets filtered through the same mask, so C is where I end up. Quick win this is not, mark it and come back if the clock is tight.
Good breakdown on the IRF mechanics, Brenda, but the sticking point is that the IRF only filters inherited rights, not explicit trustee assignments, so DCoughanour's explicit rights come through unfiltered and that is why G is the answer.
