GSEC Windows as a Service Practice Question
A security consultant is advising a company that uses Windows Update for Business to manage Windows 10 devices. The company wants to ensure that devices receive feature updates only after they have been validated by the IT team, but without using Configuration Manager. Which WUfB feature should the consultant recommend to achieve this controlled rollout?
⚠ Common exam trap
Candidates often confuse Windows Insider Program for Business with production deployment rings; Insider is for pre-release testing, while rings are for staged rollout of released updates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deployment rings with staggered deferral periods
Deployment rings with staggered deferral periods are the WUfB feature that enables a controlled rollout. By placing a small set of devices in a pilot ring with a short deferral and the rest in a broad ring with a longer deferral, IT can validate the feature update on the pilot ring before it reaches the broader population. This achieves validation without Configuration Manager. Other options are for early access, bandwidth optimization, or reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deployment rings with staggered deferral periods
Why this is correct
Deployment rings allow grouping devices into rings with different deferral periods. By assigning a pilot ring with a short deferral and a broad ring with a longer deferral, IT can validate the update on the pilot ring before it reaches the broader ring. This provides a controlled rollout without Configuration Manager. It is the recommended WUfB approach for validation.
- ✗
Windows Insider Program for Business rings
Why it's wrong here
Windows Insider Program for Business provides early access to pre-release builds for testing, but it is not a mechanism for controlled rollout of production feature updates. It is used for feedback and validation of upcoming features, not for staged deployment of released updates. This does not meet the requirement of validating updates before broad deployment.
- ✗
Update Compliance in Azure Log Analytics
Why it's wrong here
Update Compliance provides reporting and monitoring of update status across devices. It does not control the rollout or validation of updates. It can help identify issues after deployment but does not prevent updates from reaching devices. It is a monitoring tool, not a deployment control mechanism.
- ✗
Delivery Optimization peer-to-peer caching
Why it's wrong here
Delivery Optimization is a peer-to-peer caching technology that reduces bandwidth usage when downloading updates. It does not control when or to which devices updates are offered. It is unrelated to validating updates before deployment. This option is a distractor because it is an update-related feature but not a rollout control.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.