Which component of the Windows Security Infrastructure is responsible for checking the user's token against the Security Descriptor of an object to authorize access?
The SRM is the kernel-mode component that enforces access control. It validates the user's access token against the DACL on a requested object. It is the definitive authority for authorization decisions within the Windows operating system, ensuring that permissions are strictly followed for all resource access requests.
Why this answer
The Security Reference Monitor (SRM) is the core component within the Windows executive that enforces security policies. It performs the critical task of Access Check, comparing the user's security token against the object's Discretionary Access Control List (DACL). Understanding this mechanism is fundamental for any security professional, as it is the final gatekeeper for every single request to access files, registry keys, or services on a Windows system.
Exam trap
Candidates often select the 'Local Security Authority' (LSA) or 'Active Directory', confusing the high-level authentication provider with the low-level kernel component that performs the actual access check.