Courseiva

GSEC Windows Security Infrastructure Practice Question

An administrator needs to restrict sensitive file access on a Windows Server 2022 environment while ensuring that users only access resources based on their job titles. Which Windows technology should be implemented to leverage Dynamic Access Control (DAC) for this requirement?

⚠ Common exam trap

Examinees frequently confuse basic NTFS security groups with Dynamic Access Control components, selecting standard permission modification tools instead of Central Access Policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Central Access Policies

Dynamic Access Control allows administrators to apply access policies based on user claims and resource properties rather than traditional security groups alone. By integrating Active Directory claims and resource attributes, you can automate permissions, which significantly reduces the administrative overhead of managing thousands of individual NTFS permissions. This is critical for maintaining the principle of least privilege in scaling enterprise environments where group-based memberships become too complex to manage effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement Kerberos Constrained Delegation

    Why it's wrong here

    Kerberos Constrained Delegation is used to permit a service to act on behalf of a user to access resources on another server. It does not provide granular access control based on user attributes or resource claims, making it ineffective for attribute-based access control requirements in this scenario.

  • ✓

    Configure Central Access Policies

    Why this is correct

    Central Access Policies are the core component of Dynamic Access Control. They allow administrators to define resource authorization policies centrally in Active Directory and apply them to files and folders using resource properties, effectively enforcing access based on user attributes like department or job title globally.

  • ✗

    Apply AppLocker Software Restriction Policies

    Why it's wrong here

    AppLocker is designed to control which applications and scripts are allowed to execute on a system. It functions at the execution layer and does not evaluate file-level access based on user claims or resource metadata, therefore it cannot be used to restrict data access as requested.

  • ✗

    Utilize Encrypting File System (EFS)

    Why it's wrong here

    EFS provides encryption for files at rest to protect them from unauthorized access if physical storage is compromised. While it secures data, it does not provide an authorization framework based on user claims or job titles to manage access dynamically across an enterprise file server environment.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.