ACL rule evaluation?

Sumalatha2
Giga Contributor

Which one statement correctly describes access control rule evaluation?

A. if a row level rule and field level rule exist, both rules must be true before an operation is allowed

B. the role with the most permissions evaluate the rules first.

C. if more than one rule applies to a record the older rule is evaluated first.

D. Table access rules are evaluated from the general to the specific.

I am confused with the choces

1 ACCEPTED SOLUTION

Sowmya T
Tera Contributor

Hi,

Answer for this question is A. if a row level rule and field level rule exist, both rules must be true before an operation is allowed.

As an example of read access:

If the row allows access and the field denies, you could end up with a list of empty rows (just icons down the left).

If the row denies access and the fields allow, then you get nothing.

Reference:

https://docs.servicenow.com/bundle/orlando-platform-administration/page/administer/contextual-securi...

View solution in original post

6 REPLIES 6

They were not from an assessment, I am preparing for CSA certification. Some questions are confusing, The more I search about it the more I am getting confused. So I am making sure what is right. 

THANKS.

Hi,

Go with option one.

Thanks,

Dhananjay.