TechKnowSurge
NIST 800-53 AC-3 ISC2 CC 3.2 CompTIA Security+ 4.6 CompTIA Security+ 2.5 NIST NICE K0685 NIST 800-53 AC-2 NIST 800-53 AC-6 NIST CSF PR.AA-05
InteractiveSecurityFree

Effective Permissions

Thirty ACLs, seven per play: work out whether each request is allowed, explicitly denied or implicitly denied.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're doing: reading access control lists the way a system evaluates them. The lesson on access control shows two ACLs side by side, NTFS folder permissions and a router access list, and warns that they behave very differently. This set makes you apply that difference thirty times. Every question is one request at TechKnowDJ, the fictional DJ and music-tech company: a resource such as the setlist share, the royalties database, the stems bucket, the booking app or the server-room door; a three-to-five line ACL; the user's group memberships; and the action they want. Each resource is labelled with its evaluation style. Stacking ACLs add up everything the user and each of their groups is allowed, and any Deny that matches overrides all of it. First-match lists are read top to bottom and stop at the first line that fits, so a broad Deny placed above a narrow Permit quietly breaks it. There are three answers, not two, so a correct guess on "denied" is not enough. Denied explicitly means a Deny rule matched. Denied implicitly means nothing granted the request, whether because no line names the user, because Write was granted but Delete was not, because a just-in-time window closed ten minutes ago, or because an ephemeral upload token outlived its fifteen minutes. The firewall questions also cover the lesson's implicit allow for traffic from inside to outside. A few questions are least-privilege traps: the ACL allows Everyone to delete the album masters, or lets the CEO's laptop manage the core switch. The answer is still "allowed", because that is what the ACL does, and the explanation names the line least privilege would remove. Ten requests resolve each way, and every explanation walks the evaluation line by line.

What you'll learn

Aligned to

NIST 800-53
AC-3 Access Enforcement
AC-2 Account Management
AC-6 Least Privilege
ISC2 CC
3.2 Understand logical access controls
CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
2.5 Explain the purpose of mitigation techniques used to secure the enterprise.
NIST NICE
K0685 Knowledge of access control principles and practices
NIST CSF
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Key terms

Access Control List
ACL
A set of rules that defines which users or systems are granted or denied access to a resource.
Access Control Entry
ACE
An individual rule within an access control list that specifies whether to permit or deny access for a particular user, group, or traffic pattern matching defined criteria. A complete ACL is made up of an ordered sequence of ACEs.
Permissions
The defined access rights granted to users, groups, or objects that control what resources they can access or modify.
Explicit Allow
An ACL rule that specifically and intentionally permits a defined type of traffic or access to a resource.
Implicit Deny
A foundational access control principle in which any traffic or request not explicitly permitted by a rule is automatically blocked. It appears as a hidden deny-all rule at the end of every access control list.
ACL Rule Ordering
The sequential evaluation of ACL entries on a Cisco router, where the first matching rule is applied and subsequent rules are not evaluated; incorrect ordering can cause traffic to be permitted or denied unintentionally.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Just-in-Time Permissions
A practice of granting access to resources only for the specific period of time a user or system needs them, then revoking that access immediately after.
Ephemeral Credentials
Temporary account credentials provisioned for a limited time to grant access to specific resources, then removed once the need has ended.

Topics

Interactive Quiz Game

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →