Courseiva

CCNA Windows Security Infrastructure Questions

9 questions · Windows Security Infrastructure · All types, answers revealed

1
MCQmedium

Which component of the Windows Security Infrastructure is responsible for checking the user's token against the Security Descriptor of an object to authorize access?

A.Local Security Authority (LSA)
B.Security Reference Monitor (SRM)
C.Security Account Manager (SAM)
D.Active Directory Domain Services (AD DS)
AnswerB

The SRM is the kernel-mode component that enforces access control. It validates the user's access token against the DACL on a requested object. It is the definitive authority for authorization decisions within the Windows operating system, ensuring that permissions are strictly followed for all resource access requests.

Why this answer

The Security Reference Monitor (SRM) is the core component within the Windows executive that enforces security policies. It performs the critical task of Access Check, comparing the user's security token against the object's Discretionary Access Control List (DACL). Understanding this mechanism is fundamental for any security professional, as it is the final gatekeeper for every single request to access files, registry keys, or services on a Windows system.

Exam trap

Candidates often select the 'Local Security Authority' (LSA) or 'Active Directory', confusing the high-level authentication provider with the low-level kernel component that performs the actual access check.

2
MCQmedium

When configuring an Active Directory (AD) environment, which functional level is required to utilize the 'Authentication Policies' feature introduced in Windows Server 2012?

A.Windows Server 2003
B.Windows Server 2008 R2
C.Windows Server 2012
D.Windows Server 2016
AnswerC

The Windows Server 2012 domain functional level is the minimum requirement to enable Authentication Policies. This feature allows administrators to restrict which hosts an account can authenticate to, which is a powerful mechanism for limiting the blast radius of a compromised credential within the domain environment.

Why this answer

The Windows Server 2012 domain functional level introduced significant security improvements, including Authentication Policies and Silos. These allow for the restriction of account usage to specific hosts or services, effectively mitigating the risk of credential theft and lateral movement. Knowing these functional level requirements is critical for architects planning upgrades to ensure that modern security controls are available and correctly implemented across the forest.

Exam trap

Candidates often assume advanced security policies require the latest Windows Server version, overlooking that Authentication Policies were introduced in Windows Server 2012.

3
MCQmedium

A security analyst is reviewing the audit policy on a Windows Server 2022 domain controller. The analyst needs to ensure that the domain controller records detailed information about changes to user account attributes, including old and new values, to support forensic investigations. Which audit policy should the analyst enable?

A.Audit User Account Management
B.Audit Directory Service Changes
C.Audit Account Logon Events
D.Audit Policy Change
AnswerB

Audit Directory Service Changes logs events when objects in Active Directory are modified, including the old and new values of changed attributes. This policy is specifically designed to track changes to directory objects, providing the detailed information required for forensic investigations of user account modifications.

Why this answer

To capture detailed information about changes to user account attributes, including old and new values, the analyst must enable Audit Directory Service Changes. This policy logs modifications to Active Directory objects with before-and-after values, which is essential for forensic investigations. Other audit policies focus on different event types and do not provide this level of detail.

Exam trap

The trap here is confusing Audit User Account Management, which logs account management events but not detailed attribute changes, with Audit Directory Service Changes, which specifically records old and new values of modified directory objects.

4
MCQmedium

An administrator needs to restrict sensitive file access on a Windows Server 2022 environment while ensuring that users only access resources based on their job titles. Which Windows technology should be implemented to leverage Dynamic Access Control (DAC) for this requirement?

A.Implement Kerberos Constrained Delegation
B.Configure Central Access Policies
C.Apply AppLocker Software Restriction Policies
D.Utilize Encrypting File System (EFS)
AnswerB

Central Access Policies are the core component of Dynamic Access Control. They allow administrators to define resource authorization policies centrally in Active Directory and apply them to files and folders using resource properties, effectively enforcing access based on user attributes like department or job title globally.

Why this answer

Dynamic Access Control allows administrators to apply access policies based on user claims and resource properties rather than traditional security groups alone. By integrating Active Directory claims and resource attributes, you can automate permissions, which significantly reduces the administrative overhead of managing thousands of individual NTFS permissions. This is critical for maintaining the principle of least privilege in scaling enterprise environments where group-based memberships become too complex to manage effectively.

Exam trap

Examinees frequently confuse basic NTFS security groups with Dynamic Access Control components, selecting standard permission modification tools instead of Central Access Policies.

5
MCQeasy

When analyzing Windows event logs to detect brute-force activity, which Event ID indicates a failed logon attempt?

A.Event ID 4624
B.Event ID 4625
C.Event ID 4740
D.Event ID 4768
AnswerB

Event ID 4625 is the definitive log entry for a failed logon attempt in the Windows Security event log. It contains valuable metadata such as the username, source IP address, and logon type, which are necessary for identifying the origin and target of a brute-force attack.

Why this answer

Event ID 4625 is the standard Windows Security log identifier for a failed logon. Monitoring this ID is essential for identifying brute-force or credential-stuffing attacks. By correlating these logs across multiple systems, security teams can detect patterns of malicious behavior, allowing for automated account lockouts or IP blocking, which are critical components of an effective incident response strategy for Windows infrastructure.

Exam trap

Test-takers frequently confuse Event ID 4625 (failed logons) with Event ID 4624 (successful logons) when writing detection queries for brute-force attacks.

6
MCQmedium

An organization is implementing a Windows Defender Application Control (WDAC) policy to block unauthorized executables on Windows 10 endpoints. The security team wants to ensure that only signed binaries from trusted publishers are allowed to run, but they also need to allow a specific in-house application that is not signed. What is the most appropriate approach?

A.Use a hash rule to allow the specific unsigned application by its file hash.
B.Create a publisher rule for the in-house application's certificate, even though it is not signed.
C.Set WDAC to audit mode so that the unsigned application can run without being blocked.
D.Disable WDAC enforcement for the entire endpoint to allow the unsigned application to run.
AnswerA

WDAC supports hash rules, which allow executables based on their unique file hash. This is ideal for unsigned applications that need to be whitelisted. The hash ensures that only that exact file is allowed, and any modification changes the hash, preventing tampering. This approach maintains a strong security posture while permitting the necessary application.

Why this answer

WDAC allows exceptions for specific files using hash rules. This is the most appropriate method to permit an unsigned application while still enforcing the policy for all other executables. Hash rules are precise and secure because they tie the exception to the exact file content.

Disabling WDAC, using publisher rules without a signature, or switching to audit mode would either weaken security or not work.

Exam trap

The trap here is thinking that publisher rules can be used for unsigned applications, but they require a valid signature.

7
MCQhard

A security analyst is investigating a suspected credential theft attack on a Windows 10 workstation. The analyst reviews the Security event log and sees Event ID 4648 (A logon was attempted using explicit credentials) occurring repeatedly for a service account. Which of the following best describes the significance of this event in the context of credential theft?

A.It indicates that the service account was granted special privileges, such as SeDebugPrivilege, which is a common post-exploitation step.
B.It indicates that the service account's password was changed, which is a common persistence technique after credential theft.
C.It indicates that the service account was locked out due to multiple failed logon attempts, which is a sign of brute-force attack.
D.It indicates that the service account's credentials were used to run a process with explicit credentials, which could be a sign of pass-the-hash or credential reuse.
AnswerD

Event ID 4648 is logged when a process attempts to log on using explicitly provided credentials, such as when using RunAs or a scheduled task. In a credential theft scenario, an attacker might use stolen credentials to start a process, generating this event. Repeated occurrences for a service account can indicate malicious use of those credentials.

Why this answer

Event ID 4648 is generated when a logon is attempted using explicit credentials, such as with RunAs or a scheduled task. In credential theft, attackers may use stolen credentials to start processes, causing this event. Repeated occurrences for a service account can signal malicious activity.

Other events like 4625, 4740, or 4672 have different meanings and are not directly indicative of explicit credential use.

Exam trap

The trap here is assuming that any security event involving a service account indicates credential theft, without verifying the specific event ID and its meaning.

8
MCQmedium

An organization is deploying Just-In-Time (JIT) administration. Which Windows feature provides the necessary framework for creating temporary, elevated group memberships for domain administrators?

A.Restricted Groups GPO
B.Privileged Access Management (PAM)
C.User Rights Assignment policy
D.Group Policy Preferences
AnswerB

PAM provides the capability to grant time-limited, Just-In-Time administrative access. By utilizing shadow principals and the MIM platform, organizations can provision temporary group memberships, ensuring that administrative accounts do not remain privileged indefinitely, which significantly mitigates the risk associated with account compromise.

Why this answer

Privileged Access Management (PAM) using Microsoft Identity Manager (MIM) allows for the creation of shadow principals in a separate forest. This approach ensures that administrative rights are only granted for a specific window of time, drastically reducing the impact of a compromised account. This is a vital architectural pattern for securing Active Directory environments against persistent threats that rely on long-lived administrative privileges to maintain access.

Exam trap

Candidates often confuse PAM with 'Just Enough Administration' (JEA). While both are security frameworks, PAM is specific to managing time-bound administrative group memberships.

9
MCQmedium

A security administrator is hardening a Windows Server 2022 domain controller. They need to ensure that NTLM authentication is not used for any domain accounts and that only Kerberos is used. Which Group Policy setting should they configure?

A.Network security: Restrict NTLM: NTLM authentication in this domain
B.Network security: LAN Manager authentication level
C.Network security: Minimum session security for NTLM SSP based (including secure RPC) servers
D.Network security: Configure encryption types allowed for Kerberos
AnswerA

This setting allows you to deny NTLM authentication for domain accounts. When set to 'Deny all,' it blocks NTLM authentication requests for domain accounts, forcing Kerberos. This directly addresses the scenario by preventing NTLM use entirely within the domain.

Why this answer

The 'Network security: Restrict NTLM: NTLM authentication in this domain' policy explicitly controls NTLM usage for domain accounts. Setting it to 'Deny all' blocks NTLM authentication and forces Kerberos, which is the desired outcome. Other settings may harden NTLM or Kerberos but do not disable NTLM entirely.

Exam trap

The trap here is confusing settings that harden NTLM with settings that actually block NTLM authentication.

Ready to test yourself?

Try a timed practice session using only Windows Security Infrastructure questions.