Courseiva

CCNA Windows Services And Ms Cloud Questions

12 questions · Windows Services And Ms Cloud topic · All types, answers revealed

1
MCQmedium

You are troubleshooting a service startup failure on a web server. Based on the error code in the exhibit, what is the most likely cause?

A.The service account lacks the 'Log on as a service' right.
B.The service account credentials are invalid or locked.
C.The network path to the domain controller is unreachable.
D.The service binary is corrupted or missing.
AnswerB

Error 0x8007052e is the Windows system code for 'Logon failure: unknown user name or bad password'. This confirms that the service manager attempted to authenticate the service account with Active Directory, but the credentials were rejected, likely due to a password mismatch, expired password, or account lockout.

Why this answer

The error code 0x8007052e corresponds to 'Logon failure: unknown user name or bad password'. In the context of Windows services, this indicates that the credentials provided for the service account are either incorrect or the account is locked out in Active Directory. Resolving this requires verifying the account password or checking for account lockouts in the domain controller logs to ensure the service can successfully authenticate.

Exam trap

Candidates often misinterpret authentication error codes as network timeouts or registry corruption, ignoring the explicit logon failure indication provided by the code.

2
Multi-Selecthard

A security administrator is hardening a Windows Server 2022 that runs several critical services. The administrator wants to reduce the attack surface by restricting service permissions and ensuring that only authorized users can start, stop, or reconfigure services. Which TWO of the following actions should the administrator take? (Choose two.)

Select 2 answers
A.Use the Services MMC snap-in to set each service's recovery options to 'Take No Action' on failure.
B.Configure the service to log on as the Local System account to ensure it has all necessary privileges.
C.Use the SC command to set the service's security descriptor with a restricted DACL that grants only necessary permissions to specific groups.
D.Apply a Group Policy Object (GPO) that sets the startup type of unnecessary services to Disabled.
E.Grant the 'Everyone' group the right to start and stop services to simplify management.
AnswersC, D

The SC command (sc.exe) can be used to modify a service's security descriptor via the 'sdset' option. This allows an administrator to apply a custom DACL that restricts who can start, stop, or configure the service. This is a direct way to harden service permissions and reduce the attack surface by limiting access to authorized users only.

Why this answer

To harden service permissions, the administrator should restrict the service's DACL using sc.exe sdset and disable unnecessary services via GPO. These actions limit who can control services and eliminate unneeded attack vectors. Granting broad permissions or running as Local System would weaken security, and changing recovery options does not address permissions.

Exam trap

The trap here is thinking that any change to service configuration improves security; however, actions like granting broad permissions or running as Local System actually increase risk, while restricting DACLs and disabling services are genuine hardening steps.

3
MCQmedium

When auditing an Azure environment, you notice that a Virtual Machine is utilizing a User-Assigned Managed Identity. How does this differ from a System-Assigned Managed Identity?

A.User-assigned identities do not require Entra ID authentication.
B.System-assigned identities can be shared across multiple resources.
C.User-assigned identities exist as separate, independent Azure resources.
D.System-assigned identities provide more granular permission scopes.
AnswerC

A user-assigned identity is a standalone Azure resource. This allows it to be assigned to multiple Azure resources (like VMs or App Services) and managed independently of the lifecycle of those resources, providing better scalability and centralized control over permissions in complex, multi-service cloud deployments.

Why this answer

System-assigned identities are tied directly to the lifecycle of the Azure resource (e.g., the VM is deleted, the identity is deleted). User-assigned identities exist as independent resources in Azure, allowing them to be shared across multiple resources and managed independently. This flexibility is crucial for complex architectures where multiple services need to share access permissions without creating redundant identity objects, simplifying long-term identity lifecycle management and improving security granularity.

Exam trap

Many candidates confuse user-assigned and system-assigned managed identities, incorrectly believing system-assigned identities can be shared across multiple disparate Azure virtual machines.

4
MCQhard

You are auditing a Windows Server environment and identify that a service is configured to log on as a 'Group Managed Service Account' (gMSA). What is the primary security advantage of using this account type over a standard domain user account?

A.They enable Kerberos constrained delegation by default.
B.They automatically rotate passwords without service restarts.
C.They bypass the need for an SPN registration.
D.They allow for local interactive logons on all domain controllers.
AnswerB

gMSAs manage complex, long, and randomly generated passwords that are automatically rotated by the Active Directory Key Distribution Service. This eliminates the risk associated with human-managed static passwords and prevents service interruptions during rotation, ensuring that credentials are never stale or vulnerable to offline cracking attempts.

Why this answer

gMSAs provide automatic password management, where the Windows OS handles password rotation without manual intervention or service downtime. This significantly reduces the risk of password compromise or credential theft via brute-force or persistent local storage. By removing the need for human administrators to manage long-lived static credentials, gMSAs enforce a robust security posture that adheres to modern standards for service identity lifecycle management and long-term protection against credential-based lateral movement.

Exam trap

Candidates often assume the advantage is 'increased permissions' or 'easier deployment', missing the core security value of automatic password rotation which prevents long-term credential reuse.

5
MCQeasy

A security analyst is reviewing Windows event logs to detect suspicious service installations. The analyst notices Event ID 7045 in the System log, indicating a new service was installed. The service name is 'UpdaterSvc', and the image path points to a binary in a user's temp folder. The analyst wants to determine the most likely security implication of this event. Which of the following best describes the risk?

A.The service represents a potential persistence mechanism used by an attacker to maintain access to the system.
B.The event indicates a driver installation, which could cause a blue screen of death.
C.The service is likely a legitimate Windows update service, and the event can be ignored.
D.The service installation is a sign of a Windows Update failure, and the system should be rolled back.
AnswerA

Event ID 7045 indicates a new service was installed. Attackers often create services to achieve persistence, as services can be configured to start automatically at boot and run with high privileges. A binary in a user's temp folder is a red flag because legitimate services rarely reside there. This suggests the service was installed by an attacker or malicious software. Investigating the binary, its hash, and the installing user is critical. This option correctly identifies the risk of persistence, which is a common tactic in cyber attacks.

Why this answer

Event ID 7045 in the System log indicates a new service was installed. When the service binary is located in a user's temp folder, it strongly suggests malicious activity, as legitimate services are installed in protected system directories. Attackers use services for persistence because they can start automatically and run with elevated privileges.

The correct response is to treat this as a potential compromise and investigate further. The other options misinterpret the event or underestimate the risk.

Exam trap

The trap here is assuming that any service installation event is benign or related to updates, when the location of the binary is a critical indicator of compromise.

6
MCQeasy

An administrator wants to prevent unauthorized modification of Windows Services. Which tool allows for the centralized management of service startup types and logon accounts across multiple domain-joined systems?

A.Task Scheduler
B.Services.msc
C.Group Policy Management Console (GPMC)
D.Local Security Policy (secpol.msc)
AnswerC

GPMC provides the interface to define and deploy Group Policy Objects. These objects allow administrators to centrally configure service security, startup behaviors, and account permissions across the entire Active Directory domain, ensuring a uniform and auditable security baseline for all managed Windows services and host systems.

Why this answer

Group Policy Objects (GPO) are the standard mechanism in Windows environments to enforce security configurations, including service management, across an entire fleet. Centralized control ensures that security policies are applied consistently, preventing configuration drift and unauthorized changes that could be exploited by attackers. By leveraging GPOs, administrators can maintain a hardened baseline, which is a foundational requirement for both GIAC compliance standards and general enterprise cybersecurity best practices.

Exam trap

Students mistakenly choose local security policies (secpol.msc) or task scheduler utilities, forgetting that centralized multi-system management requires the Group Policy Management Console.

7
MCQhard

A security engineer is hardening a Windows Server 2019 domain controller. The organization wants to ensure that all service accounts used by critical services are managed automatically, with password rotation handled by Active Directory, and that the password is not stored locally on the server. Which of the following should the engineer implement?

A.Use virtual accounts for each service.
B.Create standard domain user accounts and configure them with a long, complex password that never expires.
C.Configure each service to use a standalone Managed Service Account (sMSA).
D.Implement Group Managed Service Accounts (gMSAs) for the services.
AnswerD

Group Managed Service Accounts (gMSAs) are domain accounts whose passwords are managed by Active Directory and rotated automatically every 30 days. They can be used across multiple servers, and the password is not stored locally; instead, the Key Distribution Service (KDS) root key is used to derive the password. This meets all the stated requirements.

Why this answer

Group Managed Service Accounts (gMSAs) are designed for automatic password management across multiple servers. Active Directory manages the password, rotating it every 30 days, and the password is not stored locally. This satisfies the need for domain-wide service accounts with no local password storage, unlike sMSAs, virtual accounts, or standard user accounts.

Exam trap

The trap here is confusing standalone Managed Service Accounts (sMSAs) with group Managed Service Accounts (gMSAs); sMSAs are limited to a single server and do not support multi-server scenarios or automatic rotation across servers.

8
MCQmedium

A security analyst is investigating a compromised Windows Server 2016 that is running an IIS web application. The analyst suspects that the attacker has created a malicious service to maintain persistence. Which of the following Windows Registry locations should the analyst examine to find the service's configuration?

A.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
B.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
C.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
AnswerA

Windows services are configured under HKLM\SYSTEM\CurrentControlSet\Services. Each subkey corresponds to a service and contains values such as ImagePath, Start, and ObjectName. A malicious service would create a subkey here. This is the correct location to examine for service persistence.

Why this answer

Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has a subkey with values like ImagePath and Start. A malicious service would create a subkey here to ensure it starts automatically.

The other locations are used for different persistence mechanisms, such as user logon scripts or are non-existent.

Exam trap

The trap here is confusing the Run keys, which are for user logon persistence, with the Services key, which is specifically for Windows service configuration.

9
MCQhard

A security engineer is hardening a Windows Server 2022 that hosts a Microsoft SQL Server instance. The server is domain-joined, and the SQL Server service currently runs under a domain user account. The engineer wants to implement a solution that provides automatic password management, supports Kerberos authentication, and allows the service to access network resources. The solution must also minimize the risk of password reuse across multiple servers. Which of the following should the engineer implement?

A.Group Managed Service Account (gMSA)
B.Standalone Managed Service Account (sMSA)
C.Virtual Service Account
D.Local Service account
AnswerA

A gMSA is a domain account whose password is managed by Active Directory and automatically rotated. It supports Kerberos authentication, allows the service to access network resources, and can be shared across multiple servers without password reuse. This directly meets all requirements and is the recommended solution for services like SQL Server.

Why this answer

A Group Managed Service Account (gMSA) is designed for services that need to access network resources and require automatic password management. It supports Kerberos and can be used across multiple servers without sharing the same password, reducing risk. The other account types either lack network access or cannot be shared across servers.

Exam trap

The trap here is confusing sMSA with gMSA; sMSA is single-server only and does not meet the multi-server requirement.

10
MCQeasy

A security administrator is reviewing the security configuration of a Windows 10 workstation. The administrator notices that the workstation has the 'Secondary Logon' service disabled. Which of the following is the MOST likely impact of this configuration?

A.Users will be unable to log on interactively to the workstation.
B.Remote Desktop connections to the workstation will be blocked.
C.Users will be unable to run applications as a different user using the 'Run as different user' option.
D.The workstation will be unable to join a domain.
AnswerC

The Secondary Logon service (seclogon) enables users to start processes under alternate credentials. If this service is disabled, the 'Run as different user' option will fail, and users will not be able to use runas.exe or Shift+right-click to launch applications with different credentials. This is the primary function of the service.

Why this answer

The Secondary Logon service is responsible for allowing users to start processes under alternate credentials. Disabling it prevents the use of 'Run as different user' and runas.exe, but does not affect interactive logon, domain join, or Remote Desktop. Therefore, the most likely impact is the inability to run applications as a different user.

Exam trap

The trap here is assuming that disabling any service will broadly impact system functionality; however, the Secondary Logon service is specifically tied to alternate credential process creation.

11
Multi-Selecthard

A security engineer is hardening a Windows Server 2022 environment that hosts several critical services. The engineer wants to implement measures to protect against credential theft and privilege escalation via service accounts. Which two of the following actions should the engineer take? (Choose two.)

Select 2 answers
A.Assign the 'Log on as a service' right to all domain users to ensure that any service can start without interruption.
B.Configure all services to run under the Local System account to simplify management and ensure they have the necessary privileges.
C.Enable the 'Store passwords using reversible encryption' policy for all service accounts to allow easy recovery of passwords if needed.
D.Implement a policy to regularly audit service accounts for excessive privileges and remove unnecessary rights, such as 'Act as part of the operating system' or 'Debug programs'.
E.Deploy Group Managed Service Accounts (gMSAs) for services that require domain authentication, ensuring automatic password management and eliminating the need for manual password updates.
AnswersD, E

Regular auditing of service account privileges helps identify and remediate excessive permissions. Rights like 'Act as part of the operating system' and 'Debug programs' are highly sensitive and should be restricted to only those accounts that absolutely require them. Removing unnecessary rights reduces the potential impact if an account is compromised. This option is correct because it enforces least privilege and helps prevent privilege escalation, aligning with hardening best practices.

Why this answer

The correct actions are to deploy gMSAs for domain-authenticated services and to audit and reduce service account privileges. gMSAs provide automatic password management and reduce credential theft risk. Auditing privileges ensures least privilege and removes dangerous rights. The other options either increase risk by granting excessive privileges or weaken security through reversible encryption or overly broad logon rights.

Exam trap

The trap here is thinking that simplifying service account management by using Local System or granting broad logon rights improves security, when in fact it expands the attack surface.

12
MCQmedium

A company uses Microsoft Entra ID (formerly Azure AD) and has a critical line-of-business application that authenticates users via SAML 2.0. The security team wants to enforce multi-factor authentication (MFA) for this application without affecting other applications. They have Entra ID P1 licenses. What is the most appropriate way to achieve this?

A.Set up a per-application MFA setting in the Enterprise Applications blade by enabling the 'Require multi-factor authentication' option for the specific application.
B.Create a new authentication method policy that restricts MFA to only the users who need access to the application.
C.Configure a Conditional Access policy that targets the specific application and requires MFA for all users.
D.Enable security defaults in Entra ID, which will automatically enforce MFA for all users and applications.
AnswerC

Conditional Access policies in Entra ID allow granular control over authentication requirements, including the ability to target specific cloud applications. By creating a policy that includes the line-of-business application as the target and requires MFA, the security team can enforce MFA only for that app. This approach leverages Entra ID P1 features and does not affect other applications. It is the recommended method for per-application MFA enforcement.

Why this answer

Conditional Access policies in Entra ID allow administrators to enforce MFA for specific applications and users. This is the most granular and appropriate method when you have Entra ID P1 licenses. Security defaults apply tenant-wide, the per-application MFA setting is deprecated, and authentication method policies do not enforce MFA per application.

Therefore, the correct solution is to create a Conditional Access policy targeting the line-of-business application.

Exam trap

The trap here is confusing tenant-wide MFA enforcement methods like security defaults with application-specific enforcement, which requires Conditional Access.

Ready to test yourself?

Try a timed practice session using only Windows Services And Ms Cloud questions.