I'm going to do my 70-290 on Friday but am a little unlcear on what best practice is for assigning share level perimissions. I've done some research and found a few things. I'm interested to see what members of this forum think.

According to this link
http://www.techexams.net/forums/viewtopic.php?t=13112, it is best practice to assign Full Control to the required groups at a share level.
Accoding to the TechNotes, there is alink to the Microsoft site that says Assign the most restrictive permissions that still allow users to perform required tasks.
Is Micosoft only referring to NTFS permissions or permissions on the whole? If they refer to both share and NTFS permissions, this can become a dog's breakfast with restrictions and so forth.
My understanding is assign "Authetnticated Users" full-control on the share (remove all other groups from the list) and then restrict everything therein using NTFS. This is what an instructor taught us at a Windows 2000 class we did for work.
I'm worried that a question will come up like "Accroinding to best practice, ..."