GSEC Windows Security Infrastructure Practice Question
When configuring an Active Directory (AD) environment, which functional level is required to utilize the 'Authentication Policies' feature introduced in Windows Server 2012?
⚠ Common exam trap
Candidates often assume advanced security policies require the latest Windows Server version, overlooking that Authentication Policies were introduced in Windows Server 2012.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Server 2012
The Windows Server 2012 domain functional level introduced significant security improvements, including Authentication Policies and Silos. These allow for the restriction of account usage to specific hosts or services, effectively mitigating the risk of credential theft and lateral movement. Knowing these functional level requirements is critical for architects planning upgrades to ensure that modern security controls are available and correctly implemented across the forest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Server 2003
Why it's wrong here
The Windows Server 2003 functional level is obsolete and does not support modern identity security features like Authentication Policies. It lacks the architectural support for claims-based authentication and Kerberos armoring, which are prerequisites for the advanced identity security features provided in later versions of Active Directory.
- ✗
Windows Server 2008 R2
Why it's wrong here
The 2008 R2 functional level does not support Authentication Policies. While it introduced features like Managed Service Accounts, the specific granular control over authentication silos and policies required the architectural updates found in the Windows Server 2012 domain functional level, making it insufficient for this requirement.
- ✓
Windows Server 2012
Why this is correct
The Windows Server 2012 domain functional level is the minimum requirement to enable Authentication Policies. This feature allows administrators to restrict which hosts an account can authenticate to, which is a powerful mechanism for limiting the blast radius of a compromised credential within the domain environment.
- ✗
Windows Server 2016
Why it's wrong here
While the 2016 level supports Authentication Policies, it is not the minimum requirement. Organizations can achieve this functionality at the 2012 level. Stating 2016 as the requirement is technically inaccurate, as it implies older, still-supported environments cannot utilize these critical security controls, which is incorrect.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.