CompTIA Server+ (SK0-005)TroubleshootingHard

A server administrator is investigating why a critical application is failing to start after a recent operating system patch. The application's logs show 'Access Denied' errors when attempting to write to its data directory, even though the directory permissions appear correct for the service account. The server is running Windows Server, and the service account is a member of the 'Administrators' group. Which of the following security features is MOST likely interfering with the application?

  1. AWindows Firewall.
  2. BNetwork Level Authentication (NLA).
  3. CData Execution Prevention (DEP).
  4. DUser Account Control (UAC).
Show answer & explanation

Correct answer: D. User Account Control (UAC).

Even if a service account is part of the 'Administrators' group, User Account Control (UAC) in Windows Server can prevent applications from writing to certain system-protected locations or performing elevated actions without explicit consent, even for administrators. A recent OS patch could have tightened UAC policies or affected how the application interacts with UAC, leading to 'Access Denied' errors despite seemingly correct permissions.

Why the other options are wrong

  • A. Windows Firewall controls network access, not file system write permissions, and would typically show connection errors.
  • B. NLA is a Remote Desktop Services security feature and would affect RDP connections, not local application file access.
  • C. DEP is a memory protection feature that prevents execution of code from non-executable memory regions; it would cause application crashes or specific memory access violations, not 'Access Denied' for file writes.

User Account Control (UAC)

A Windows security feature that helps prevent unauthorized changes to the operating system by prompting for administrative approval, even for administrators, when attempting actions that require elevated privileges.

  • Restricts even administrator accounts by default.
  • Requires elevation for certain system-level actions.
  • Can interfere with applications expecting full administrator rights.

Memory trick: Access denied, even as admin? UAC's probably trying to win.

More Troubleshooting questions