A system administrator needs to ensure that a critical Windows service runs with the least privilege necessary while still maintaining access to a local database. Which account type provides a unique SID, limited network privileges, and a virtual account profile?
Trap 1: LocalSystem account
LocalSystem is a highly privileged account that functions as the computer identity on the network. It possesses extensive rights, including full access to local resources and the ability to act as the machine in Active Directory, which violates the principle of least privilege required for basic database service operations.
Trap 2: NetworkService account
NetworkService provides limited local access but carries the computer's identity on the network. This makes it unsuitable for restricted environments because the service account's network activities are indistinguishable from the machine account, potentially granting excessive access to domain resources that the specific database application does not actually require.
Trap 3: LocalService account
LocalService is a built-in account with minimal local privileges and no network access. While secure, it lacks the specific identity features and managed nature required for modern service configurations that need to interact with local database subsystems while maintaining a secure, unique SID profile for auditing and security policy enforcement.
- A
LocalSystem account
Why it fails: LocalSystem is a highly privileged account that functions as the computer identity on the network. It possesses extensive rights, including full access to local resources and the ability to act as the machine in Active Directory, which violates the principle of least privilege required for basic database service operations.
- B
NetworkService account
Why it fails: NetworkService provides limited local access but carries the computer's identity on the network. This makes it unsuitable for restricted environments because the service account's network activities are indistinguishable from the machine account, potentially granting excessive access to domain resources that the specific database application does not actually require.
- C
Virtual Account
Virtual accounts are managed local accounts with no password requirement. They are designed for running services while providing unique SIDs and restricted access permissions. They automatically handle password changes and provide isolation, ensuring that services do not possess unnecessary administrative rights that could be exploited by a malicious actor.
- D
LocalService account
Why it fails: LocalService is a built-in account with minimal local privileges and no network access. While secure, it lacks the specific identity features and managed nature required for modern service configurations that need to interact with local database subsystems while maintaining a secure, unique SID profile for auditing and security policy enforcement.