Courseiva

GSEC Windows Services and MS Cloud Practice Question

An administrator wants to prevent unauthorized modification of Windows Services. Which tool allows for the centralized management of service startup types and logon accounts across multiple domain-joined systems?

⚠ Common exam trap

Students mistakenly choose local security policies (secpol.msc) or task scheduler utilities, forgetting that centralized multi-system management requires the Group Policy Management Console.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Group Policy Management Console (GPMC)

Group Policy Objects (GPO) are the standard mechanism in Windows environments to enforce security configurations, including service management, across an entire fleet. Centralized control ensures that security policies are applied consistently, preventing configuration drift and unauthorized changes that could be exploited by attackers. By leveraging GPOs, administrators can maintain a hardened baseline, which is a foundational requirement for both GIAC compliance standards and general enterprise cybersecurity best practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Task Scheduler

    Why it's wrong here

    Task Scheduler is designed to run automated scripts or programs at specific intervals. It is not an enterprise management tool for enforcing security policies or managing Windows service configurations across a domain, and using it for such tasks would lead to inconsistent security postures and management overhead.

  • ✗

    Services.msc

    Why it's wrong here

    Services.msc is a local management console. While it allows for manual service configuration, it lacks the capability to push settings to multiple machines or enforce consistent security policies, making it ineffective for managing large-scale server environments where consistency is required to mitigate potential security vulnerabilities.

  • ✓

    Group Policy Management Console (GPMC)

    Why this is correct

    GPMC provides the interface to define and deploy Group Policy Objects. These objects allow administrators to centrally configure service security, startup behaviors, and account permissions across the entire Active Directory domain, ensuring a uniform and auditable security baseline for all managed Windows services and host systems.

  • ✗

    Local Security Policy (secpol.msc)

    Why it's wrong here

    Secpol.msc is a local configuration tool restricted to the machine it is run on. It does not provide the centralized management required for enterprise-wide security enforcement, leaving the environment vulnerable to configuration drift across different servers, which is a major risk factor in maintaining a secure infrastructure.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.