Courseiva

GSEC · topic practice

Windows Services and MS Cloud practice questions

This GSEC domain covers hardening and managing Windows services and Microsoft cloud identity. Questions test service disablement effects, credential-theft protections like LSA protection and Credential Guard, SAML 2.0 and MFA enforcement in Entra ID, and centralized service configuration via Group Policy. Expect scenario-based items requiring you to pick the correct control or tool.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Windows Services and MS Cloud

What the exam tests

What to know about Windows Services and MS Cloud

Be able to identify what each Windows service controls, select the right credential-theft mitigation, and configure Entra ID Conditional Access for SAML apps. The single most important thing: know that centralized service startup and logon account changes are deployed through Group Policy, not local tools.

Effects of disabling Secondary Logon and other Windows services

Credential Guard, LSA protection, and service account hardening against theft

Entra ID SAML 2.0 app configuration and Conditional Access MFA enforcement

Group Policy Preferences for centralized service startup type and logon account management

Watch out for

Common Windows Services and MS Cloud exam traps

  • ▸Assuming disabling Secondary Logon breaks all logons; it only blocks RunAs and secondary credentials, not interactive sign-in.
  • ▸Confusing Credential Guard with LSA protection; each defends different credential material and requires specific hardware or configuration.
  • ▸Enforcing MFA directly on a SAML app instead of via Conditional Access, missing the supported Entra ID policy path.

Practice set

Windows Services and MS Cloud questions

20 questions · select your answer, then reveal the explanation

A system administrator needs to ensure that a critical Windows service runs with the least privilege necessary while still maintaining access to a local database. Which account type provides a unique SID, limited network privileges, and a virtual account profile?

Question 2mediummultiple choice
Read the full VPN explanation →

An administrator observes that the policy in the exhibit is failing to provide access to an authorized user working from a corporate VPN. The user's external IP is 203.0.113.5. What is the root cause of this access failure?

Exhibit

Refer to the exhibit: {"Effect": "Allow", "Action": ["s3:GetObject"], "Resource": ["arn:aws:s3:::production-data/*"], "Condition": {"IpAddress": {"aws:SourceIp": "192.168.1.0/24"}}}

Which TWO of the following actions are best practice when securing Azure AD (Entra ID) service principals used for automated CI/CD pipelines?

Which THREE of the following are critical hardening steps for an Azure App Service hosting a sensitive public-facing web application?

A security analyst is reviewing a Windows Server 2022 event log and sees repeated Event ID 4625 (An account failed to log on) with Logon Type 4. The account name is a domain service account used by a custom backup service. Which of the following is the MOST likely explanation for these failed logon attempts?

An administrator is auditing a Windows Server 2019 file server and notices that a scheduled task is configured to run under the built-in SYSTEM account. The task executes a PowerShell script that writes to a network share on a different server. The script fails with an access denied error when attempting to write to the share. The administrator confirms that the share permissions and NTFS permissions allow the computer account of the file server to write. What is the most likely reason for the failure?

A security administrator is investigating a potential compromise of a Windows Server that runs a custom service. The service is configured to log on as a domain user account, and the administrator suspects the account's credentials were dumped from memory. Which Windows security event ID should the administrator search for to detect attempts to access the Local Security Authority Subsystem Service (LSASS) process?

A security engineer is reviewing a Windows Server 2022 domain controller's security log and notices Event ID 4625 (An account failed to log on) with Logon Type 3 and the process name 'lsass.exe'. The source workstation is a member server that hosts a service configured to run under a domain user account. The engineer suspects the service is failing because the account's password has expired. Which of the following is the most likely cause of the failed logons?

You are auditing a Windows Server environment and identify that a service is configured to log on as a 'Group Managed Service Account' (gMSA). What is the primary security advantage of using this account type over a standard domain user account?

An administrator wants to prevent unauthorized modification of Windows Services. Which tool allows for the centralized management of service startup types and logon accounts across multiple domain-joined systems?

When auditing an Azure environment, you notice that a Virtual Machine is utilizing a User-Assigned Managed Identity. How does this differ from a System-Assigned Managed Identity?

You are troubleshooting a service startup failure on a web server. Based on the error code in the exhibit, what is the most likely cause?

Exhibit

Refer to the exhibit: {"Error": "Service did not start due to logon failure", "ErrorCode": "0x8007052e", "LogonAccount": "DOMAIN\svc_app", "Machine": "SRV-WEB-01"}

A security engineer is hardening a Windows Server 2022 that hosts a Microsoft SQL Server instance. The server is domain-joined, and the SQL Server service currently runs under a domain user account. The engineer wants to implement a solution that provides automatic password management, supports Kerberos authentication, and allows the service to access network resources. The solution must also minimize the risk of password reuse across multiple servers. Which of the following should the engineer implement?

A security engineer is hardening a Windows Server 2019 domain controller. The organization wants to ensure that all service accounts used by critical services are managed automatically, with password rotation handled by Active Directory, and that the password is not stored locally on the server. Which of the following should the engineer implement?

A security administrator is reviewing the security configuration of a Windows 10 workstation. The administrator notices that the workstation has the 'Secondary Logon' service disabled. Which of the following is the MOST likely impact of this configuration?

A security analyst is investigating a compromised Windows Server 2016 that is running an IIS web application. The analyst suspects that the attacker has created a malicious service to maintain persistence. Which of the following Windows Registry locations should the analyst examine to find the service's configuration?

A security administrator is hardening a Windows Server 2022 that runs several critical services. The administrator wants to reduce the attack surface by restricting service permissions and ensuring that only authorized users can start, stop, or reconfigure services. Which TWO of the following actions should the administrator take? (Choose two.)

A security analyst is reviewing Windows event logs to detect suspicious service installations. The analyst notices Event ID 7045 in the System log, indicating a new service was installed. The service name is 'UpdaterSvc', and the image path points to a binary in a user's temp folder. The analyst wants to determine the most likely security implication of this event. Which of the following best describes the risk?

A security engineer is hardening a Windows Server 2022 environment that hosts several critical services. The engineer wants to implement measures to protect against credential theft and privilege escalation via service accounts. Which two of the following actions should the engineer take? (Choose two.)

A company uses Microsoft Entra ID (formerly Azure AD) and has a critical line-of-business application that authenticates users via SAML 2.0. The security team wants to enforce multi-factor authentication (MFA) for this application without affecting other applications. They have Entra ID P1 licenses. What is the most appropriate way to achieve this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Windows Services and MS Cloud sessions

Start a Windows Services and MS Cloud only practice session

Every question in these sessions is drawn from the Windows Services and MS Cloud domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Windows Services and MS Cloud?
Be able to identify what each Windows service controls, select the right credential-theft mitigation, and configure Entra ID Conditional Access for SAML apps. The single most important thing: know that centralized service startup and logon account changes are deployed through Group Policy, not local tools.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Windows Services and MS Cloud questions in a focused session?
Yes — the session launcher on this page draws every question from the Windows Services and MS Cloud domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.