Courseiva

GSEC Windows Security Infrastructure Practice Question

When configuring an Active Directory (AD) environment, which functional level is required to utilize the 'Authentication Policies' feature introduced in Windows Server 2012?

⚠ Common exam trap

Candidates often assume advanced security policies require the latest Windows Server version, overlooking that Authentication Policies were introduced in Windows Server 2012.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Server 2012

The Windows Server 2012 domain functional level introduced significant security improvements, including Authentication Policies and Silos. These allow for the restriction of account usage to specific hosts or services, effectively mitigating the risk of credential theft and lateral movement. Knowing these functional level requirements is critical for architects planning upgrades to ensure that modern security controls are available and correctly implemented across the forest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Server 2003

    Why it's wrong here

    The Windows Server 2003 functional level is obsolete and does not support modern identity security features like Authentication Policies. It lacks the architectural support for claims-based authentication and Kerberos armoring, which are prerequisites for the advanced identity security features provided in later versions of Active Directory.

  • ✗

    Windows Server 2008 R2

    Why it's wrong here

    The 2008 R2 functional level does not support Authentication Policies. While it introduced features like Managed Service Accounts, the specific granular control over authentication silos and policies required the architectural updates found in the Windows Server 2012 domain functional level, making it insufficient for this requirement.

  • ✓

    Windows Server 2012

    Why this is correct

    The Windows Server 2012 domain functional level is the minimum requirement to enable Authentication Policies. This feature allows administrators to restrict which hosts an account can authenticate to, which is a powerful mechanism for limiting the blast radius of a compromised credential within the domain environment.

  • ✗

    Windows Server 2016

    Why it's wrong here

    While the 2016 level supports Authentication Policies, it is not the minimum requirement. Organizations can achieve this functionality at the 2012 level. Stating 2016 as the requirement is technically inaccurate, as it implies older, still-supported environments cannot utilize these critical security controls, which is incorrect.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.