Free GIAC Security Essentials practice — 6 questions on Windows Security, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Windows Security
A security analyst wants to detect Kerberoasting attempts against service accounts in an Active Directory domain by monitoring the security event log on domain controllers. Which combination of Event ID and characteristic is the MOST reliable indicator of Kerberoasting activity?
Kerberoasting requests a TGS (Event ID 4769) for a service account's SPN. Legitimate modern clients typically negotiate AES, so a flood of TGS requests using the weaker RC4 (0x17) encryption type against accounts with SPNs — especially from a single source in a short time window — is the classic Kerberoasting signature that offline hash-cracking tools rely on.
Question 2 of 6 · Windows Security
A network of shared kiosk workstations sits in a dedicated OU with a GPO that must apply specific user-side desktop restrictions to ANY user who logs on, completely disregarding the GPOs normally applied to that user's own account in their home OU. Which Group Policy loopback processing mode should be configured on the kiosk GPO?
Replace mode causes the computer's list of GPOs to be used entirely in place of the user's normal GPO list during user policy processing, meaning only the kiosk computer's linked GPOs apply to the user session, regardless of what OU the user account lives in.
Question 3 of 6 · Windows Security
Domain administrator accounts have been added to the Protected Users security group in a domain running at the Windows Server 2012 R2 (or higher) domain functional level. Which security benefit does this change PRIMARILY provide?
Protected Users is a security-only group that changes how Windows handles authentication for its members: it prevents NTLM authentication, blocks use of DES/RC4 Kerberos encryption types (forcing AES), disables credential caching, disables CredSSP/WDigest credential delegation, and disallows unconstrained/constrained delegation — directly hardening the account against pass-the-hash and credential theft.
Question 4 of 6 · Windows Security
An organization wants to use AppLocker/WDAC rules to restrict PowerShell so that, even if a script somehow bypasses the execution policy, an attacker cannot use .NET reflection, arbitrary COM object instantiation, or Add-Type to load and execute unmanaged code — while still allowing use of approved cmdlets and basic scripting constructs. Which PowerShell language mode accomplishes this?
ConstrainedLanguage mode is designed specifically for this scenario: it allows approved core PowerShell types and cmdlets (typically those from modules trusted by WDAC/AppLocker) while blocking direct .NET method invocation, COM object creation, Add-Type, and arbitrary type conversion, sharply reducing an attacker's ability to execute arbitrary unmanaged code even from an otherwise-functional script.
Question 5 of 6 · Windows Security
Which statement correctly differentiates LSASS Protected Process Light (RunAsPPL) from Windows Defender Credential Guard?
RunAsPPL configures LSASS as a Protected Process Light, requiring any code (including drivers) that wants to open a handle to LSASS to be signed at an equal or higher protection level — this stops many userland/kernel credential-dumping techniques but a compromised kernel-mode driver can still potentially bypass it. Credential Guard goes further, using Virtualization-Based Security (Hyper-V) to run an isolated LSA process (LSAISO) in a separate secure VM-like container so that secrets are not exposed even to a fully compromised kernel.
Question 6 of 6 · Windows Security
A security team wants to detect when someone modifies the SACL (audit configuration) on a sensitive file share in order to weaken future monitoring of that object, as opposed to merely changing who can read or write to it. Which Windows Security Event ID specifically records this action?
Event ID 4907 specifically logs changes to an object's auditing (SACL) settings, which is exactly the scenario of an attacker or insider disabling or altering audit logging on a sensitive object to evade detection.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.