Courseiva

GSEC Windows Services and MS Cloud Practice Question

A security engineer is hardening a Windows Server 2022 that hosts a Microsoft SQL Server instance. The server is domain-joined, and the SQL Server service currently runs under a domain user account. The engineer wants to implement a solution that provides automatic password management, supports Kerberos authentication, and allows the service to access network resources. The solution must also minimize the risk of password reuse across multiple servers. Which of the following should the engineer implement?

⚠ Common exam trap

Watch out — candidates often confuse sMSA with gMSA; sMSA is single-server only and does not meet the multi-server requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Group Managed Service Account (gMSA)

A Group Managed Service Account (gMSA) is designed for services that need to access network resources and require automatic password management. It supports Kerberos and can be used across multiple servers without sharing the same password, reducing risk. The other account types either lack network access or cannot be shared across servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Group Managed Service Account (gMSA)

    Why this is correct

    A gMSA is a domain account whose password is managed by Active Directory and automatically rotated. It supports Kerberos authentication, allows the service to access network resources, and can be shared across multiple servers without password reuse. This directly meets all requirements and is the recommended solution for services like SQL Server.

  • ✗

    Standalone Managed Service Account (sMSA)

    Why it's wrong here

    An sMSA provides automatic password management but is limited to a single server. It cannot be shared across multiple servers, so it does not meet the requirement to minimize password reuse across multiple servers. Also, sMSAs are deprecated in favor of gMSAs for multi-server scenarios.

  • ✗

    Virtual Service Account

    Why it's wrong here

    Virtual accounts are local to the machine and cannot access network resources with domain credentials. They are managed automatically but do not support Kerberos authentication to remote resources. This fails both the network access and Kerberos requirements.

  • ✗

    Local Service account

    Why it's wrong here

    The Local Service account is a built-in account with minimal privileges on the local machine. It cannot authenticate to network resources using domain credentials and does not support Kerberos. It also cannot be used for services requiring domain access. This fails the network resource access requirement.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.