GSEC Windows as a Service Practice Question
A security analyst is reviewing the update history of a Windows 10 Enterprise device managed by Windows Update for Business (WUfB). The analyst notices that a critical security update was installed 30 days after its release, even though no deferral policies were configured. Which factor is the most likely cause for the delayed installation?
⚠ Common exam trap
The trap here is assuming that without deferral policies, updates install immediately, overlooking device availability and connectivity requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The device was offline or in sleep mode during the update's initial release period.
The most likely cause is that the device was offline or inactive during the update's release. WUfB does not force immediate installation; it relies on the device being on and connected to download and install updates. Without deferral policies, updates are offered as soon as they are released, but installation depends on device availability. A 30-day delay aligns with a device that was not used or connected for an extended period, after which it received the update upon becoming active.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The device was configured to use a Windows Update for Business deferral for quality updates.
Why it's wrong here
If a deferral for quality updates were configured, the delay would be intentional and consistent with the deferral period. However, the scenario states that no deferral policies were configured, so this cannot be the cause. The delay must be due to another factor such as network connectivity, update approval, or device activity. Therefore, this option is incorrect because it contradicts the given information that no deferral policies were set.
- ✗
The update was blocked by a Windows Defender Application Control (WDAC) policy.
Why it's wrong here
WDAC policies control which applications and binaries are allowed to run, but they do not block Windows updates. Updates are delivered by the Windows Update service, which is not subject to WDAC application control. A WDAC policy could potentially block the update executable if misconfigured, but that is not a typical cause and would likely result in an error rather than a delayed installation. Therefore, this is not the most likely cause.
- ✓
The device was offline or in sleep mode during the update's initial release period.
Why this is correct
Windows Update for Business schedules updates based on device activity and connectivity. If the device is offline, in sleep mode, or not connected to the internet during the update's release, it will not download and install the update until it becomes active and connected. This can cause delays even without deferral policies. The 30-day delay suggests the device missed the initial release window due to being offline or inactive, which is a common cause in WUfB environments.
- ✗
The update was not approved in Windows Server Update Services (WSUS).
Why it's wrong here
WSUS approval is a factor when devices are managed by WSUS, not WUfB. WUfB devices receive updates directly from Microsoft Update or Windows Update, bypassing WSUS. If WSUS were in use, the scenario would mention it. Since the device is managed by WUfB, WSUS approval is irrelevant. Thus, this option is not the cause; the delay likely stems from WUfB-specific behavior or device conditions.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.