nerdexam
Novell

050-696 · Question #24

Novell 050-696 Exam User BDevries has access to his manager's confidential files located on the HR volume on the DA2 NetWare server. Upon inspection, you discover that his user object has all file…

The correct answer is A. Groups BDevries is a member of. E. Organizational roles BDevries is an occupant of. When unexpected eDirectory or file system rights appear on a user, administrators must trace all sources of security equivalence, including group memberships and organizational role occupancies.

File System and Storage Management

Question

Novell 050-696 Exam User BDevries has access to his manager's confidential files located on the HR volume on the DA2 NetWare server. Upon inspection, you discover that his user object has all file system rights to the root directory of the HR volume. You determine that BDevries has the Supervisor effective right to the DA2 server object in the eDirectory tree. What should you check to identify where these rights are coming from? (Choose 2.)

Options

  • AGroups BDevries is a member of.
  • BList objects associated with BDevries.
  • CAlias objects associated with BDevries.
  • DTemplate objects associated with BDevries.
  • EOrganizational roles BDevries is an occupant of.
  • FNDSPredicateStats objects associated with BDevries.

How the community answered

(54 responses)
  • A
    81% (44)
  • B
    6% (3)
  • C
    2% (1)
  • D
    2% (1)
  • F
    9% (5)

Why each option

When unexpected eDirectory or file system rights appear on a user, administrators must trace all sources of security equivalence, including group memberships and organizational role occupancies.

AGroups BDevries is a member of.Correct

Group membership grants all eDirectory and file system rights assigned to the Group object to every member, so BDevries could have acquired Supervisor rights through membership in a privileged group.

BList objects associated with BDevries.

Listing objects associated with a user enumerates related objects but does not identify sources of trustee assignments or security equivalences that grant file system rights.

CAlias objects associated with BDevries.

Alias objects are simply pointers to another object in the tree and do not independently grant rights - they share the same effective rights as the original object they reference.

DTemplate objects associated with BDevries.

Template objects define default property values when a user object is created but do not maintain an ongoing security equivalence or rights assignment to the created user afterward.

EOrganizational roles BDevries is an occupant of.Correct

Organizational Role objects can hold trustee assignments, and any user who occupies such a role inherits those rights as a security equivalence, making this a common but overlooked source of elevated access.

FNDSPredicateStats objects associated with BDevries.

NDSPredicateStats objects are internal NDS performance and diagnostics structures, not security or trustee assignment objects, and have no bearing on a user's effective rights.

Concept tested: Tracing eDirectory effective rights sources and security equivalences

Source: https://www.novell.com/documentation/edir88/edir88/data/fbachifb.html

Topics

#file system rights#security equivalence#group membership#organizational roles

Community Discussion

No community discussion yet for this question.

Full 050-696 Practice