If you try to set a only permission combination on the checkboxes, the powerful Access Control Custom editor is shown where you can configure the following ACE in detail. Please note that the propagation could be aware somewhere in the subtree of an object. Just deactivate the Reason permissions from parent objects option. If you do that, you can use whether you keep all the inherited entries as real entries, or if you keep to remove all the inherited entries from the ACL..
Please note that you can easily change the scope value according to the current scope type. Just click on the scope label directly in the regarding row and choose the new scope from the pulldown list: Please be aware of the fact that there are combinations of checkboxes which are NOT possible or not allowed to set in one single ACL line.
You cannot set the permission to read a certain attribute on the one hand and the permission to create a certain object class on the other hand in the sam access control entry.