CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security engineer is hardening a Windows Server that hosts a critical enterprise application. The application runs as a service, and its service account requires minimal privileges to perform its functions, specifically to access a network share on another server. The engineer wants to ensure that the service account's password is automatically managed by the domain and rotated regularly without manual intervention. Which type of account should be used?

  1. ANetwork Service Account
  2. BGroup Managed Service Account (gMSA)
  3. CLocal Service Account
  4. DUser Account with Restricted Permissions
Show answer & explanation

Correct answer: B. Group Managed Service Account (gMSA)

Group Managed Service Accounts (gMSAs) are designed for services that need to run on multiple servers (like accessing a network share) while providing automatic password management, simplified service principal name (SPN) management, and delegation of management to other administrators. They enhance security by eliminating static passwords and reducing the risk of credential compromise.

Why the other options are wrong

  • A. Network Service accounts can access network resources using the computer's credentials, but they do not offer automatic password management or the flexibility of gMSAs for multiple hosts.
  • C. Local Service accounts have limited local privileges and cannot access network resources as described.
  • D. A regular user account requires manual password management and rotation, which is explicitly what the engineer wants to avoid.

Group Managed Service Account (gMSA)

A gMSA is a type of Active Directory account for services that provides automatic password management, simplified SPN management, and delegation of management to other administrators.

  • Eliminates the need for manual password rotation.
  • Suitable for services running on multiple servers.
  • Enhances security by reducing static credentials.

Memory trick: Local is just here, Network uses the machine, gMSA manages itself for groups.

More Security Engineering questions