050-696 · Question #24
Novell 050-696 Exam User BDevries has access to his manager's confidential files located on the HR volume on the DA2 NetWare server. Upon inspection, you discover that his user object has all file…
The correct answer is A. Groups BDevries is a member of. E. Organizational roles BDevries is an occupant of. When unexpected eDirectory or file system rights appear on a user, administrators must trace all sources of security equivalence, including group memberships and organizational role occupancies.
Question
Options
- AGroups BDevries is a member of.
- BList objects associated with BDevries.
- CAlias objects associated with BDevries.
- DTemplate objects associated with BDevries.
- EOrganizational roles BDevries is an occupant of.
- FNDSPredicateStats objects associated with BDevries.
How the community answered
(54 responses)- A81% (44)
- B6% (3)
- C2% (1)
- D2% (1)
- F9% (5)
Why each option
When unexpected eDirectory or file system rights appear on a user, administrators must trace all sources of security equivalence, including group memberships and organizational role occupancies.
Group membership grants all eDirectory and file system rights assigned to the Group object to every member, so BDevries could have acquired Supervisor rights through membership in a privileged group.
Listing objects associated with a user enumerates related objects but does not identify sources of trustee assignments or security equivalences that grant file system rights.
Alias objects are simply pointers to another object in the tree and do not independently grant rights - they share the same effective rights as the original object they reference.
Template objects define default property values when a user object is created but do not maintain an ongoing security equivalence or rights assignment to the created user afterward.
Organizational Role objects can hold trustee assignments, and any user who occupies such a role inherits those rights as a security equivalence, making this a common but overlooked source of elevated access.
NDSPredicateStats objects are internal NDS performance and diagnostics structures, not security or trustee assignment objects, and have no bearing on a user's effective rights.
Concept tested: Tracing eDirectory effective rights sources and security equivalences
Source: https://www.novell.com/documentation/edir88/edir88/data/fbachifb.html
Topics
Community Discussion
No community discussion yet for this question.