Courseiva

GSEC · domain

Windows Security Infrastructure

This domain covers Windows authentication, authorization, and privilege management mechanisms tested on GSEC. You must identify which OS functional levels enable specific AD features, interpret Security event logs for credential theft, recognize JIT administration frameworks, and explain how the access check works between a user's token and an object's security descriptor.

9 questions1 easy7 medium1 hard

Focused practice

Practice Windows Security Infrastructure questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Windows Security Infrastructure

A candidate must be able to configure and troubleshoot Windows authentication and authorization, including AD functional levels, event log interpretation, and JIT frameworks. The single most important thing is correctly mapping access tokens to security descriptors for authorization decisions.

Active Directory functional levels required for Authentication Policies and Silo features

Security event log analysis for credential theft, including Event ID 4648

Just-In-Time administration using Privileged Access Management and temporal group membership

Authorization process: comparing a user's access token against an object's security descriptor

Watch out for

Common Windows Security Infrastructure exam traps

  • ▸Assuming any domain functional level supports Authentication Policies; it requires Windows Server 2012 R2 or higher.
  • ▸Confusing Event ID 4648 (explicit credentials) with 4624 (logon) or 4672 (special privileges).
  • ▸Believing JIT administration is native to all Windows versions; it requires Microsoft Identity Manager or PAM trust.

Question index

All Windows Security Infrastructure questions (9)

Click any question to see the full explanation, or start a practice session above.

1

Which component of the Windows Security Infrastructure is responsible for checking the user's token against the Security Descriptor of an object to authorize access?

Medium
2

When configuring an Active Directory (AD) environment, which functional level is required to utilize the 'Authentication Policies' feature introduced in Windows Server 2012?

Medium
3

A security analyst is reviewing the audit policy on a Windows Server 2022 domain controller. The analyst needs to ensure that the domain controller records detailed information about changes to user account attributes, including old and new values, to support forensic investigations. Which audit policy should the analyst enable?

Medium
4

An administrator needs to restrict sensitive file access on a Windows Server 2022 environment while ensuring that users only access resources based on their job titles. Which Windows technology should be implemented to leverage Dynamic Access Control (DAC) for this requirement?

Medium
5

When analyzing Windows event logs to detect brute-force activity, which Event ID indicates a failed logon attempt?

Easy
6

An organization is implementing a Windows Defender Application Control (WDAC) policy to block unauthorized executables on Windows 10 endpoints. The security team wants to ensure that only signed binaries from trusted publishers are allowed to run, but they also need to allow a specific in-house application that is not signed. What is the most appropriate approach?

Medium
7

A security analyst is investigating a suspected credential theft attack on a Windows 10 workstation. The analyst reviews the Security event log and sees Event ID 4648 (A logon was attempted using explicit credentials) occurring repeatedly for a service account. Which of the following best describes the significance of this event in the context of credential theft?

Hard
8

An organization is deploying Just-In-Time (JIT) administration. Which Windows feature provides the necessary framework for creating temporary, elevated group memberships for domain administrators?

Medium
9

A security administrator is hardening a Windows Server 2022 domain controller. They need to ensure that NTLM authentication is not used for any domain accounts and that only Kerberos is used. Which Group Policy setting should they configure?

Medium

Frequently asked questions

What does the Windows Security Infrastructure domain cover on the GSEC exam?
A candidate must be able to configure and troubleshoot Windows authentication and authorization, including AD functional levels, event log interpretation, and JIT frameworks. The single most important thing is correctly mapping access tokens to security descriptors for authorization decisions.
How many questions are in this domain?
This page lists all 9 Windows Security Infrastructure questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Windows Security Infrastructure questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC windows security infrastructure Practice Questions