CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security engineer is hardening a Windows Server that hosts a critical enterprise application. The application runs under a dedicated service account, and the organization requires that this account's password be automatically managed by Active Directory, rotated regularly, and never directly known by administrators. This minimizes the risk of credential compromise. Which type of Active Directory account BEST satisfies these requirements?

  1. ALocal Service Account
  2. BGroup Managed Service Account (gMSA)
  3. CUser Account
  4. DBuilt-in Administrator Account
Show answer & explanation

Correct answer: B. Group Managed Service Account (gMSA)

A Group Managed Service Account (gMSA) is a special type of Active Directory account designed for services. It allows Windows services to run with automatic password management, rotation, and distribution across multiple servers. Administrators do not need to know the password, significantly reducing the risk of credential compromise.

Why the other options are wrong

  • A. Local Service Accounts are managed locally on the server and do not support automatic password management by Active Directory or distribution across multiple servers.
  • C. Standard User Accounts require manual password management and rotation, which is contrary to the requirement for automatic management and not knowing the password.
  • D. Built-in Administrator Accounts have high privileges and require manual password management, making them unsuitable for running applications with automated, secure credential handling.

Group Managed Service Account (gMSA)

An Active Directory account type used for services that provides automatic password management, simplified service principal name (SPN) management, and delegation of management to other administrators.

  • Automatic password rotation and management by AD
  • Admins never know the password
  • Can be used across multiple servers for a service

Memory trick: gMSA: Great for Services, Managed Automatically!

More Security Engineering questions