Courseiva

GSEC Windows Security Infrastructure Practice Question

A security administrator is hardening a Windows Server 2022 domain controller. They need to ensure that NTLM authentication is not used for any domain accounts and that only Kerberos is used. Which Group Policy setting should they configure?

⚠ Common exam trap

It's easy for candidates to confuse settings that harden NTLM with settings that actually block NTLM authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network security: Restrict NTLM: NTLM authentication in this domain

The 'Network security: Restrict NTLM: NTLM authentication in this domain' policy explicitly controls NTLM usage for domain accounts. Setting it to 'Deny all' blocks NTLM authentication and forces Kerberos, which is the desired outcome. Other settings may harden NTLM or Kerberos but do not disable NTLM entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network security: Restrict NTLM: NTLM authentication in this domain

    Why this is correct

    This setting allows you to deny NTLM authentication for domain accounts. When set to 'Deny all,' it blocks NTLM authentication requests for domain accounts, forcing Kerberos. This directly addresses the scenario by preventing NTLM use entirely within the domain.

  • ✗

    Network security: LAN Manager authentication level

    Why it's wrong here

    This setting controls the challenge/response authentication protocol used for NTLM, such as LM, NTLM, or NTLMv2. It does not disable NTLM entirely; it only restricts weaker variants. It would not prevent NTLM authentication, so it fails to meet the requirement.

  • ✗

    Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

    Why it's wrong here

    This setting requires message integrity and confidentiality for NTLM SSP-based communications. It does not prevent NTLM authentication; it only enforces security flags. NTLM could still be used, so it does not satisfy the goal of eliminating NTLM.

  • ✗

    Network security: Configure encryption types allowed for Kerberos

    Why it's wrong here

    This setting specifies which Kerberos encryption types are permitted, such as AES or RC4. It does not affect NTLM authentication and would not block NTLM. It is relevant for Kerberos hardening but not for disabling NTLM.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.