GSEC Windows Services and MS Cloud Practice Question
A security engineer is hardening a Windows Server 2022 environment that hosts several critical services. The engineer wants to implement measures to protect against credential theft and privilege escalation via service accounts. Which two of the following actions should the engineer take? (Choose two.)
⚠ Common exam trap
The trap here is thinking that simplifying service account management by using Local System or granting broad logon rights improves security, when in fact it expands the attack surface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a policy to regularly audit service accounts for excessive privileges and remove unnecessary rights, such as 'Act as part of the operating system' or 'Debug programs'.
The correct actions are to deploy gMSAs for domain-authenticated services and to audit and reduce service account privileges. gMSAs provide automatic password management and reduce credential theft risk. Auditing privileges ensures least privilege and removes dangerous rights. The other options either increase risk by granting excessive privileges or weaken security through reversible encryption or overly broad logon rights.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the 'Log on as a service' right to all domain users to ensure that any service can start without interruption.
Why it's wrong here
Granting the 'Log on as a service' right to all domain users is a severe security misconfiguration. It would allow any user account to be used to run a service, increasing the risk of privilege escalation and lateral movement. Service accounts should be specifically designated and granted this right only when necessary. This option is incorrect because it broadens the attack surface and violates least privilege.
- ✗
Configure all services to run under the Local System account to simplify management and ensure they have the necessary privileges.
Why it's wrong here
Running services as Local System grants them extensive privileges on the local machine, which violates the principle of least privilege. If an attacker compromises such a service, they gain full control of the system. Instead, services should run under dedicated accounts with minimal rights. This option is incorrect because it increases the attack surface and does not protect against credential theft or privilege escalation; it actually exacerbates the risk.
- ✗
Enable the 'Store passwords using reversible encryption' policy for all service accounts to allow easy recovery of passwords if needed.
Why it's wrong here
Storing passwords with reversible encryption is a security risk because it allows passwords to be decrypted and read by anyone with access to the system. This policy is intended for legacy applications and should be avoided. Enabling it for service accounts would make credential theft easier, not harder. Therefore, this option is incorrect and would weaken security rather than harden it.
- ✓
Implement a policy to regularly audit service accounts for excessive privileges and remove unnecessary rights, such as 'Act as part of the operating system' or 'Debug programs'.
Why this is correct
Regular auditing of service account privileges helps identify and remediate excessive permissions. Rights like 'Act as part of the operating system' and 'Debug programs' are highly sensitive and should be restricted to only those accounts that absolutely require them. Removing unnecessary rights reduces the potential impact if an account is compromised. This option is correct because it enforces least privilege and helps prevent privilege escalation, aligning with hardening best practices.
- ✓
Deploy Group Managed Service Accounts (gMSAs) for services that require domain authentication, ensuring automatic password management and eliminating the need for manual password updates.
Why this is correct
gMSAs provide automatic password management, complex passwords, and the ability to run services without interactive logon. They reduce the risk of credential theft because passwords are not known to administrators and are rotated regularly. They also support least privilege by allowing specific permissions to be granted to the gMSA. This is a recommended practice for securing service accounts in a domain environment. This option is correct as it directly addresses credential theft and privilege escalation.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.