A candidate must be able to configure and troubleshoot Windows authentication and authorization, including AD functional levels, event log interpretation, and JIT frameworks. The single most important thing is correctly mapping access tokens to security descriptors for authorization decisions.
Start practicing
Windows Security Infrastructure — choose a session length
Free · No account required
Domain overview
This domain covers Windows authentication, authorization, and privilege management mechanisms tested on GSEC. You must identify which OS functional levels enable specific AD features, interpret Security event logs for credential theft, recognize JIT administration frameworks, and explain how the access check works between a user's token and an object's security descriptor.
Exam objectives
Active Directory functional levels required for Authentication Policies and Silo features
Security event log analysis for credential theft, including Event ID 4648
Just-In-Time administration using Privileged Access Management and temporal group membership
Authorization process: comparing a user's access token against an object's security descriptor
Assuming any domain functional level supports Authentication Policies; it requires Windows Server 2012 R2 or higher.
Confusing Event ID 4648 (explicit credentials) with 4624 (logon) or 4672 (special privileges).
Believing JIT administration is native to all Windows versions; it requires Microsoft Identity Manager or PAM trust.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator needs to restrict sensitive file access on a Windows Server 2022 environment while ensuring that users only access resources based on their job titles. Which Windows technology should be implemented to leverage Dynamic Access Control (DAC) for this requirement?
2When analyzing Windows event logs to detect brute-force activity, which Event ID indicates a failed logon attempt?
3An organization is deploying Just-In-Time (JIT) administration. Which Windows feature provides the necessary framework for creating temporary, elevated group memberships for domain administrators?
4When configuring an Active Directory (AD) environment, which functional level is required to utilize the 'Authentication Policies' feature introduced in Windows Server 2012?
5Which component of the Windows Security Infrastructure is responsible for checking the user's token against the Security Descriptor of an object to authorize access?
6A security administrator is hardening a Windows Server 2022 domain controller. They need to ensure that NTLM authentication is not used for any domain accounts and that only Kerberos is used. Which Group Policy setting should they configure?
7A security analyst is investigating a suspected credential theft attack on a Windows 10 workstation. The analyst reviews the Security event log and sees Event ID 4648 (A logon was attempted using explicit credentials) occurring repeatedly for a service account. Which of the following best describes the significance of this event in the context of credential theft?
8An organization is implementing a Windows Defender Application Control (WDAC) policy to block unauthorized executables on Windows 10 endpoints. The security team wants to ensure that only signed binaries from trusted publishers are allowed to run, but they also need to allow a specific in-house application that is not signed. What is the most appropriate approach?
9A security analyst is reviewing the audit policy on a Windows Server 2022 domain controller. The analyst needs to ensure that the domain controller records detailed information about changes to user account attributes, including old and new values, to support forensic investigations. Which audit policy should the analyst enable?
A candidate must be able to configure and troubleshoot Windows authentication and authorization, including AD functional levels, event log interpretation, and JIT frameworks. The single most important thing is correctly mapping access tokens to security descriptors for authorization decisions.
The Courseiva GSEC question bank contains 9 questions in the Windows Security Infrastructure domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Windows Security Infrastructure domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included