CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security engineer is hardening a Windows Server that hosts a critical enterprise application. The organization's security policy requires that all system-level processes and services run with the minimum necessary privileges to perform their functions. Which of the following Windows features or concepts is MOST relevant to implementing this principle of least privilege for services?

  1. AUser Account Control (UAC)
  2. BService Accounts and Managed Service Accounts (MSAs/gMSAs)
  3. CWindows Firewall with Advanced Security
  4. DData Execution Prevention (DEP)
Show answer & explanation

Correct answer: B. Service Accounts and Managed Service Accounts (MSAs/gMSAs)

Service Accounts and especially Managed Service Accounts (MSAs) or group Managed Service Accounts (gMSAs) in Windows are specifically designed to allow services to run under dedicated, low-privilege identities. MSAs/gMSAs automate password management and simplify service principal name (SPN) management, ensuring that services operate with only the permissions required, thereby adhering to the principle of least privilege. This directly addresses the requirement for system-level processes and services to run with minimum necessary privileges.

Why the other options are wrong

  • A. UAC helps prevent unauthorized changes by requiring administrator approval for certain actions, but it's primarily for interactive user sessions, not for configuring the privilege level of background services.
  • C. Windows Firewall controls network traffic access to and from the server, but it does not manage the internal process privileges of services.
  • D. DEP is a memory protection feature that prevents malicious code from executing in non-executable memory regions; it's a runtime protection, not a mechanism for configuring service privileges.

Managed Service Accounts (MSAs/gMSAs)

Managed Service Accounts (MSAs) and group Managed Service Accounts (gMSAs) are special types of domain accounts in Active Directory designed to provide automatic password management, simplified SPN management, and delegation of management to other administrators, for services and scheduled tasks.

  • Automate password rotation for service accounts.
  • Provide principle of least privilege for services.
  • Eliminate need for manual password updates for services.
  • gMSAs allow multiple servers to share the same service account.

Memory trick: MSAs Make Services Minimal Privilege

More Security Engineering questions