GSEC Windows Security Infrastructure Practice Question
A security administrator is hardening a Windows Server 2022 domain controller. They need to ensure that NTLM authentication is not used for any domain accounts and that only Kerberos is used. Which Group Policy setting should they configure?
⚠ Common exam trap
It's easy for candidates to confuse settings that harden NTLM with settings that actually block NTLM authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network security: Restrict NTLM: NTLM authentication in this domain
The 'Network security: Restrict NTLM: NTLM authentication in this domain' policy explicitly controls NTLM usage for domain accounts. Setting it to 'Deny all' blocks NTLM authentication and forces Kerberos, which is the desired outcome. Other settings may harden NTLM or Kerberos but do not disable NTLM entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Network security: Restrict NTLM: NTLM authentication in this domain
Why this is correct
This setting allows you to deny NTLM authentication for domain accounts. When set to 'Deny all,' it blocks NTLM authentication requests for domain accounts, forcing Kerberos. This directly addresses the scenario by preventing NTLM use entirely within the domain.
- ✗
Network security: LAN Manager authentication level
Why it's wrong here
This setting controls the challenge/response authentication protocol used for NTLM, such as LM, NTLM, or NTLMv2. It does not disable NTLM entirely; it only restricts weaker variants. It would not prevent NTLM authentication, so it fails to meet the requirement.
- ✗
Network security: Minimum session security for NTLM SSP based (including secure RPC) servers
Why it's wrong here
This setting requires message integrity and confidentiality for NTLM SSP-based communications. It does not prevent NTLM authentication; it only enforces security flags. NTLM could still be used, so it does not satisfy the goal of eliminating NTLM.
- ✗
Network security: Configure encryption types allowed for Kerberos
Why it's wrong here
This setting specifies which Kerberos encryption types are permitted, such as AES or RC4. It does not affect NTLM authentication and would not block NTLM. It is relevant for Kerberos hardening but not for disabling NTLM.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.