GSEC Windows as a Service Practice Question
An enterprise network administrator needs to manage Windows 10 feature updates across a heterogeneous fleet containing both Enterprise and Professional editions. Which deployment methodology natively supports setting a target release version to freeze clients on a specific version like 21H2 while blocking automatic upgrades to later versions?
⚠ Common exam trap
Candidates frequently confuse Windows Update for Business with WSUS or SCCM. They often select the wrong management tool because they are unaware of the specific 'target release version' policy setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Update for Business configured via Group Policy to specify a target release version
Setting a target release version through Group Policy or Mobile Device Management allows administrators to freeze workstations on a specific Windows 10 feature update, such as 21H2. This control prevents automatic upgrades to newer major OS versions, ensuring mission-critical line-of-business applications remain compatible without requiring immediate manual intervention across every individual endpoint device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Update for Business configured via Group Policy to specify a target release version
Why this is correct
Windows Update for Business enables administrators to define a specific target version, such as Windows 10 version 21H2, directly through Group Policy or MDM solutions. This capability ensures endpoints remain pinned to that exact release until the policy is explicitly changed, preventing unexpected disruptions from subsequent annual feature upgrades.
- ✗
Windows Server Update Services automatic approval rules targeting all newly released operating system updates
Why it's wrong here
WSUS automatic approval rules inherently approve the latest released updates rather than restricting clients to a specific older target version. Relying solely on automatic rules would immediately push newer feature updates to clients, defeating the primary operational requirement to freeze workstations on version 21H2.
- ✗
Consumer Windows Update settings modified through local registry edits on each individual workstation
Why it's wrong here
Relying on manual local registry modifications does not provide scalable enterprise-level control or reliable enforcement across a large fleet. Local settings can be easily overwritten by standard Windows Update behavior or user intervention, making this approach unsuitable for strict regulatory or operational environments.
- ✗
Delivery Optimization peer-to-peer distribution bandwidth throttling applied via Local Group Policy
Why it's wrong here
Delivery Optimization strictly manages bandwidth consumption and peer-to-peer sharing efficiency for downloaded packages across the local network. It lacks any functionality to govern which operating system feature update versions are approved for installation or targeted to endpoints.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.