GSEC Windows Security Infrastructure Practice Question
An administrator needs to restrict sensitive file access on a Windows Server 2022 environment while ensuring that users only access resources based on their job titles. Which Windows technology should be implemented to leverage Dynamic Access Control (DAC) for this requirement?
⚠ Common exam trap
Examinees frequently confuse basic NTFS security groups with Dynamic Access Control components, selecting standard permission modification tools instead of Central Access Policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Central Access Policies
Dynamic Access Control allows administrators to apply access policies based on user claims and resource properties rather than traditional security groups alone. By integrating Active Directory claims and resource attributes, you can automate permissions, which significantly reduces the administrative overhead of managing thousands of individual NTFS permissions. This is critical for maintaining the principle of least privilege in scaling enterprise environments where group-based memberships become too complex to manage effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement Kerberos Constrained Delegation
Why it's wrong here
Kerberos Constrained Delegation is used to permit a service to act on behalf of a user to access resources on another server. It does not provide granular access control based on user attributes or resource claims, making it ineffective for attribute-based access control requirements in this scenario.
- ✓
Configure Central Access Policies
Why this is correct
Central Access Policies are the core component of Dynamic Access Control. They allow administrators to define resource authorization policies centrally in Active Directory and apply them to files and folders using resource properties, effectively enforcing access based on user attributes like department or job title globally.
- ✗
Apply AppLocker Software Restriction Policies
Why it's wrong here
AppLocker is designed to control which applications and scripts are allowed to execute on a system. It functions at the execution layer and does not evaluate file-level access based on user claims or resource metadata, therefore it cannot be used to restrict data access as requested.
- ✗
Utilize Encrypting File System (EFS)
Why it's wrong here
EFS provides encryption for files at rest to protect them from unauthorized access if physical storage is compromised. While it secures data, it does not provide an authorization framework based on user claims or job titles to manage access dynamically across an enterprise file server environment.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.