Courseiva

GSEC Windows Services and MS Cloud Practice Question

A security engineer is hardening a Windows Server 2019 domain controller. The organization wants to ensure that all service accounts used by critical services are managed automatically, with password rotation handled by Active Directory, and that the password is not stored locally on the server. Which of the following should the engineer implement?

⚠ Common exam trap

Watch out — candidates often confuse standalone Managed Service Accounts (sMSAs) with group Managed Service Accounts (gMSAs); sMSAs are limited to a single server and do not support multi-server scenarios or automatic rotation across servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement Group Managed Service Accounts (gMSAs) for the services.

Group Managed Service Accounts (gMSAs) are designed for automatic password management across multiple servers. Active Directory manages the password, rotating it every 30 days, and the password is not stored locally. This satisfies the need for domain-wide service accounts with no local password storage, unlike sMSAs, virtual accounts, or standard user accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use virtual accounts for each service.

    Why it's wrong here

    Virtual accounts are local accounts that are automatically managed by the operating system and do not require password management. However, they are local to the server and cannot be used for domain-level services or across multiple servers. They also do not provide centralized management or password rotation via Active Directory.

  • ✗

    Create standard domain user accounts and configure them with a long, complex password that never expires.

    Why it's wrong here

    Standard domain user accounts with static passwords do not provide automatic password rotation and require manual management. They also increase the risk of credential theft because the password is stored locally in the service configuration. This approach violates the principle of least privilege and does not meet the requirement for automatic management.

  • ✗

    Configure each service to use a standalone Managed Service Account (sMSA).

    Why it's wrong here

    Standalone Managed Service Accounts (sMSAs) are supported only on the local server and cannot be used across multiple servers. They also do not support automatic password rotation when used on multiple servers. The requirement for domain-wide management and no local password storage is better met by a group Managed Service Account (gMSA).

  • ✓

    Implement Group Managed Service Accounts (gMSAs) for the services.

    Why this is correct

    Group Managed Service Accounts (gMSAs) are domain accounts whose passwords are managed by Active Directory and rotated automatically every 30 days. They can be used across multiple servers, and the password is not stored locally; instead, the Key Distribution Service (KDS) root key is used to derive the password. This meets all the stated requirements.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.