How are ACL default permissions enforced on a directory?

A systems administrator created a new directory with specific permissions. Given the following output: # file: comptia # owner: root * group: root user::rwx group::r-x other::--- default:user::rwx default:group::r-x default:group:wheel:rwx default:mask::rwx default:other::--- Which of the following permissions are enforced on /comptia?

  1. Members of the wheel group can read files in /comptia. Source Reference Answer
  2. Newly created files in /comptia will have the sticky bit set.
  3. Other users can create files in /comptia.
  4. Only root can create flies in /comptia.

Community Votes

A
83%
D
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to interpret ACL output and distinguish between permissions on the directory itself versus permissions inherited by new files; the common trap is confusing default ACL entries (which apply to new files) with the directory's own ACL.

This question tests understanding of POSIX Access Control Lists (ACLs) and how default ACL entries apply to newly created files and subdirectories within a directory. Community consensus confirms that the default:group:wheel:rwx entry grants wheel group members full access to new files, making option A correct.

Many candidates choose D, incorrectly assuming that default ACLs affect who can create files in the directory itself. In reality, default ACLs only apply to newly created files and subdirectories, not to the directory's own access permissions.

Community Discussion (3 comments)

HappyDay030303 👍 1 Selected: D
wheel group has rwx in default ACLs this only applies to new files created inside — not to access of /comptia itself Only root can create files in /comptia.
rcano1234 👍 3 Selected: A
A. Members of the wheel group can read files in /comptia: The default:group:wheel:rwx entry in the output indicates that members of the wheel group have read, write, and execute permissions on files created within the /comptia directory.
sterguy 👍 2 Selected: A
Is it not the wheel house group can read files? it not saying can only read files but they can indeed read the files?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The output shows default:group:wheel:rwx, which means any new file or subdirectory created inside /comptia will inherit an ACL entry granting the wheel group read, write, and execute permissions. Since wheel group members have read access (rwx includes r), option A is correct. The directory's own ACL (group::r-x) restricts the owning group to read and execute, but the default ACL specifically governs new file permissions.

Why the Other Options Are Wrong

Option B is wrong because the sticky bit is a special permission not indicated by any ACL entry; there is no default:other::--- with sticky bit notation. Option C is wrong because default:other::--- explicitly denies all permissions to other users on new files. Option D is wrong because default ACLs apply to new files created inside the directory, not to the directory itself; the directory's own permissions (user::rwx, group::r-x, other::---) determine who can create files in /comptia.

Community Comment Notes

Comment [1] correctly identifies that default:group:wheel:rwx grants wheel group members rwx on new files. Comment [2] raises a valid point about whether wheel members can "only read" versus "can read" — the ACL grants rwx, which includes read, so A is accurate. Comment [3] incorrectly argues for D by confusing default ACLs with directory permissions; default ACLs do not control who can create files in the directory itself.

Official Reference

Exam Strategy

When analyzing ACL output, always distinguish between the directory's own permissions (user::, group::, other::) and default permissions (default:*) which apply to new files. Remember that default ACLs never affect access to the directory itself.

Related Analysis

← Back to XK0-005 Study Guide