Courseiva

GSEC Windows Services and MS Cloud Practice Question

When auditing an Azure environment, you notice that a Virtual Machine is utilizing a User-Assigned Managed Identity. How does this differ from a System-Assigned Managed Identity?

⚠ Common exam trap

Many candidates confuse user-assigned and system-assigned managed identities, incorrectly believing system-assigned identities can be shared across multiple disparate Azure virtual machines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User-assigned identities exist as separate, independent Azure resources.

System-assigned identities are tied directly to the lifecycle of the Azure resource (e.g., the VM is deleted, the identity is deleted). User-assigned identities exist as independent resources in Azure, allowing them to be shared across multiple resources and managed independently. This flexibility is crucial for complex architectures where multiple services need to share access permissions without creating redundant identity objects, simplifying long-term identity lifecycle management and improving security granularity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User-assigned identities do not require Entra ID authentication.

    Why it's wrong here

    All Azure Managed Identities rely on Entra ID (Azure AD) for authentication. They provide an automatically managed identity in Microsoft Entra ID, allowing services to authenticate to other cloud resources without storing credentials, regardless of whether the identity is user-assigned or system-assigned.

  • ✗

    System-assigned identities can be shared across multiple resources.

    Why it's wrong here

    System-assigned identities are exclusively linked to a single Azure resource. They cannot be shared or reused across different VMs or services. This limitation is the primary distinction that necessitates the use of user-assigned identities when a shared access profile is required for a group of resources.

  • ✓

    User-assigned identities exist as separate, independent Azure resources.

    Why this is correct

    A user-assigned identity is a standalone Azure resource. This allows it to be assigned to multiple Azure resources (like VMs or App Services) and managed independently of the lifecycle of those resources, providing better scalability and centralized control over permissions in complex, multi-service cloud deployments.

  • ✗

    System-assigned identities provide more granular permission scopes.

    Why it's wrong here

    Both types of identities support the same RBAC scopes. The difference between them is purely operational—lifecycle management and resource association—not the level of granularity or the type of security policies that can be applied to the identity within the Azure Resource Manager framework.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.