Know which tool governs which update type and edition: WUfB for cloud-managed deferrals and rings, WSUS for on-premises approval and targeting. The single most important thing is matching the management method to the device edition and update category before choosing a deployment strategy.
Start practicing
Windows as a Service — choose a session length
Free · No account required
Domain overview
This domain covers servicing Windows 10 and 11 Enterprise under Windows as a Service: feature-update cadence, Windows Update for Business (WUfB), Windows Server Update Services (WSUS), and deployment rings. GSEC questions test which tool controls which update type, how deferrals and deadlines behave, and how edition and management method constrain your options.
Exam objectives
Windows Update for Business deferral policies for quality and feature updates
WSUS synchronization, approval, and Group Policy targeting of clients
Windows 10/11 Enterprise feature update release cadence and servicing channels
Deployment rings, deadlines, and active hours for controlled rollout
Assuming WUfB can set a feature-update target version for Professional edition the same way as Enterprise.
Confusing quality (security) update deferrals with feature update deferrals, which have different maximums and behavior.
Believing WSUS and WUfB can both fully manage the same device without conflict or precedence rules.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise network administrator needs to manage Windows 10 feature updates across a heterogeneous fleet containing both Enterprise and Professional editions. Which deployment methodology natively supports setting a target release version to freeze clients on a specific version like 21H2 while blocking automatic upgrades to later versions?
2Microsoft releases major Windows feature updates under a predictable cadence as part of the Windows as a Service model. How often are Windows 10 and Windows 11 Enterprise feature updates officially released under the modern servicing model?
3An IT security team is auditing Windows Update for Business configurations across a multi-site enterprise. Which TWO methods can be utilized by administrators to successfully deploy and enforce these cloud-linked update policies? (Choose TWO)
4A security administrator is troubleshooting an enterprise client that repeatedly fails to complete a major Windows feature upgrade, automatically triggering a rollback. Which built-in command-line utility should the administrator use to examine detailed migration logs, error codes, and rollback triggers?
5A security analyst is reviewing the update history of a Windows 10 Enterprise device managed by Windows Update for Business (WUfB). The analyst notices that a critical security update was installed 30 days after its release, even though no deferral policies were configured. Which factor is the most likely cause for the delayed installation?
6A security administrator manages a fleet of Windows 10 Enterprise devices that must remain on version 1809 because a critical line-of-business application is only certified for that build. The organization uses Windows Update for Business (WUfB) and wants to prevent these devices from receiving feature updates for 18 months while still receiving quality updates. Which WUfB setting should the administrator configure?
7A security consultant is advising a company that uses Windows Update for Business to manage Windows 10 devices. The company wants to ensure that devices receive feature updates only after they have been validated by the IT team, but without using Configuration Manager. Which WUfB feature should the consultant recommend to achieve this controlled rollout?
8A security administrator is planning to deploy Windows 10 feature updates to a pilot group of devices using Windows Update for Business. The administrator wants to ensure that the pilot group receives the feature update before the rest of the organization, so that any issues can be identified early. Which Windows Update for Business configuration should the administrator use?
9A security administrator is troubleshooting a Windows 10 Enterprise device that is not receiving feature updates from Windows Update for Business. The administrator confirms that the device is connected to the network and has the correct Windows Update for Business policies applied. The administrator suspects that a Group Policy setting is overriding the Windows Update for Business configuration. Which Group Policy setting should the administrator check first?
10A security administrator manages a Windows 10 Enterprise deployment where devices are currently on version 1909. The organization wants to upgrade to version 21H2 while ensuring that the upgrade does not install on devices with incompatible drivers. The administrator decides to use a Windows Update for Business deployment ring. Which of the following best describes the purpose of the deployment ring in this context?
Know which tool governs which update type and edition: WUfB for cloud-managed deferrals and rings, WSUS for on-premises approval and targeting. The single most important thing is matching the management method to the device edition and update category before choosing a deployment strategy.
The Courseiva GSEC question bank contains 10 questions in the Windows as a Service domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Windows as a Service domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included