GSEC · domain
Windows Services and MS Cloud
This GSEC domain covers hardening and managing Windows services and Microsoft cloud identity. Questions test service disablement effects, credential-theft protections like LSA protection and Credential Guard, SAML 2.0 and MFA enforcement in Entra ID, and centralized service configuration via Group Policy. Expect scenario-based items requiring you to pick the correct control or tool.
Focused practice
Practice Windows Services and MS Cloud questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Windows Services and MS Cloud
Be able to identify what each Windows service controls, select the right credential-theft mitigation, and configure Entra ID Conditional Access for SAML apps. The single most important thing: know that centralized service startup and logon account changes are deployed through Group Policy, not local tools.
Effects of disabling Secondary Logon and other Windows services
Credential Guard, LSA protection, and service account hardening against theft
Entra ID SAML 2.0 app configuration and Conditional Access MFA enforcement
Group Policy Preferences for centralized service startup type and logon account management
Watch out for
Common Windows Services and MS Cloud exam traps
- ▸Assuming disabling Secondary Logon breaks all logons; it only blocks RunAs and secondary credentials, not interactive sign-in.
- ▸Confusing Credential Guard with LSA protection; each defends different credential material and requires specific hardware or configuration.
- ▸Enforcing MFA directly on a SAML app instead of via Conditional Access, missing the supported Entra ID policy path.
Question index
All Windows Services and MS Cloud questions (12)
Click any question to see the full explanation, or start a practice session above.
You are troubleshooting a service startup failure on a web server. Based on the error code in the exhibit, what is the most likely cause?
Medium2A security administrator is hardening a Windows Server 2022 that runs several critical services. The administrator wants to reduce the attack surface by restricting service permissions and ensuring that only authorized users can start, stop, or reconfigure services. Which TWO of the following actions should the administrator take? (Choose two.)
Hard3When auditing an Azure environment, you notice that a Virtual Machine is utilizing a User-Assigned Managed Identity. How does this differ from a System-Assigned Managed Identity?
Medium4You are auditing a Windows Server environment and identify that a service is configured to log on as a 'Group Managed Service Account' (gMSA). What is the primary security advantage of using this account type over a standard domain user account?
Hard5A security analyst is reviewing Windows event logs to detect suspicious service installations. The analyst notices Event ID 7045 in the System log, indicating a new service was installed. The service name is 'UpdaterSvc', and the image path points to a binary in a user's temp folder. The analyst wants to determine the most likely security implication of this event. Which of the following best describes the risk?
Easy6An administrator wants to prevent unauthorized modification of Windows Services. Which tool allows for the centralized management of service startup types and logon accounts across multiple domain-joined systems?
Easy7A security engineer is hardening a Windows Server 2019 domain controller. The organization wants to ensure that all service accounts used by critical services are managed automatically, with password rotation handled by Active Directory, and that the password is not stored locally on the server. Which of the following should the engineer implement?
Hard8A security analyst is investigating a compromised Windows Server 2016 that is running an IIS web application. The analyst suspects that the attacker has created a malicious service to maintain persistence. Which of the following Windows Registry locations should the analyst examine to find the service's configuration?
Medium9A security engineer is hardening a Windows Server 2022 that hosts a Microsoft SQL Server instance. The server is domain-joined, and the SQL Server service currently runs under a domain user account. The engineer wants to implement a solution that provides automatic password management, supports Kerberos authentication, and allows the service to access network resources. The solution must also minimize the risk of password reuse across multiple servers. Which of the following should the engineer implement?
Hard10A security administrator is reviewing the security configuration of a Windows 10 workstation. The administrator notices that the workstation has the 'Secondary Logon' service disabled. Which of the following is the MOST likely impact of this configuration?
Easy11A security engineer is hardening a Windows Server 2022 environment that hosts several critical services. The engineer wants to implement measures to protect against credential theft and privilege escalation via service accounts. Which two of the following actions should the engineer take? (Choose two.)
Hard12A company uses Microsoft Entra ID (formerly Azure AD) and has a critical line-of-business application that authenticates users via SAML 2.0. The security team wants to enforce multi-factor authentication (MFA) for this application without affecting other applications. They have Entra ID P1 licenses. What is the most appropriate way to achieve this?
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Windows Services and MS Cloud domain cover on the GSEC exam?
- Be able to identify what each Windows service controls, select the right credential-theft mitigation, and configure Entra ID Conditional Access for SAML apps. The single most important thing: know that centralized service startup and logon account changes are deployed through Group Policy, not local tools.
- How many questions are in this domain?
- This page lists all 12 Windows Services and MS Cloud questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Windows Services and MS Cloud questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.