GSEC Windows Services and MS Cloud Practice Question
A security administrator is reviewing the security configuration of a Windows 10 workstation. The administrator notices that the workstation has the 'Secondary Logon' service disabled. Which of the following is the MOST likely impact of this configuration?
⚠ Common exam trap
The trap here is assuming that disabling any service will broadly impact system functionality; however, the Secondary Logon service is specifically tied to alternate credential process creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Users will be unable to run applications as a different user using the 'Run as different user' option.
The Secondary Logon service is responsible for allowing users to start processes under alternate credentials. Disabling it prevents the use of 'Run as different user' and runas.exe, but does not affect interactive logon, domain join, or Remote Desktop. Therefore, the most likely impact is the inability to run applications as a different user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Users will be unable to log on interactively to the workstation.
Why it's wrong here
Interactive logon is handled by the Winlogon service and other components, not the Secondary Logon service. Disabling Secondary Logon does not prevent users from logging on normally with their primary credentials. It only affects the ability to start processes with alternate credentials.
- ✗
Remote Desktop connections to the workstation will be blocked.
Why it's wrong here
Remote Desktop connections depend on the Remote Desktop Services service (TermService) and related components. The Secondary Logon service is not required for RDP. Disabling it will not block Remote Desktop, although it may affect the ability to run applications as a different user within an RDP session.
- ✓
Users will be unable to run applications as a different user using the 'Run as different user' option.
Why this is correct
The Secondary Logon service (seclogon) enables users to start processes under alternate credentials. If this service is disabled, the 'Run as different user' option will fail, and users will not be able to use runas.exe or Shift+right-click to launch applications with different credentials. This is the primary function of the service.
- ✗
The workstation will be unable to join a domain.
Why it's wrong here
Domain join operations rely on the Netlogon service and other networking components. The Secondary Logon service is not involved in domain join. Disabling it will not prevent the workstation from joining a domain or from authenticating domain users.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.