How are ACL default permissions enforced on a directory?
A systems administrator created a new directory with specific permissions. Given the following output: # file: comptia # owner: root * group: root user::rwx group::r-x other::--- default:user::rwx default:group::r-x default:group:wheel:rwx default:mask::rwx default:other::--- Which of the following permissions are enforced on /comptia?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to interpret ACL output and distinguish between permissions on the directory itself versus permissions inherited by new files; the common trap is confusing default ACL entries (which apply to new files) with the directory's own ACL.
This question tests understanding of POSIX Access Control Lists (ACLs) and how default ACL entries apply to newly created files and subdirectories within a directory. Community consensus confirms that the default:group:wheel:rwx entry grants wheel group members full access to new files, making option A correct.
Many candidates choose D, incorrectly assuming that default ACLs affect who can create files in the directory itself. In reality, default ACLs only apply to newly created files and subdirectories, not to the directory's own access permissions.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The output showsdefault:group:wheel:rwx, which means any new file or subdirectory created inside /comptia will inherit an ACL entry granting the wheel group read, write, and execute permissions. Since wheel group members have read access (rwx includes r), option A is correct. The directory's own ACL (group::r-x) restricts the owning group to read and execute, but the default ACL specifically governs new file permissions.Why the Other Options Are Wrong
Option B is wrong because the sticky bit is a special permission not indicated by any ACL entry; there is nodefault:other::--- with sticky bit notation. Option C is wrong because default:other::--- explicitly denies all permissions to other users on new files. Option D is wrong because default ACLs apply to new files created inside the directory, not to the directory itself; the directory's own permissions (user::rwx, group::r-x, other::---) determine who can create files in /comptia.Community Comment Notes
Comment [1] correctly identifies thatdefault:group:wheel:rwx grants wheel group members rwx on new files. Comment [2] raises a valid point about whether wheel members can "only read" versus "can read" — the ACL grants rwx, which includes read, so A is accurate. Comment [3] incorrectly argues for D by confusing default ACLs with directory permissions; default ACLs do not control who can create files in the directory itself. Official Reference
Exam Strategy
When analyzing ACL output, always distinguish between the directory's own permissions (user::, group::, other::) and default permissions (default:*) which apply to new files. Remember that default ACLs never affect access to the directory itself.