CompTIA SecurityX (CAS-005)Security EngineeringHard
A security engineer is tasked with hardening a Windows Server that hosts a critical enterprise application. The application uses several services that require access to network resources (e.g., file shares, databases) on other servers. Historically, these services ran under highly privileged domain accounts, posing a significant security risk. The engineer needs to implement a solution that allows these services to securely authenticate to network resources with their own unique, automatically managed identities, without requiring manual password management or granting excessive privileges. Which Windows Server feature is BEST suited for this scenario?
- ANetwork Service Account
- BLocal Service Account
- CGroup Managed Service Account (gMSA)
- DLocal System Account
Show answer & explanationAnswer & explanation
Correct answer: C. Group Managed Service Account (gMSA)
Group Managed Service Accounts (gMSAs) are designed for services that require access to network resources. They provide automatic password management, simplified service principal name (SPN) management, and the ability to run across multiple servers, addressing the security risks of manually managed or highly privileged accounts.
Why the other options are wrong
- A. The Network Service account has limited privileges on the local computer and presents the computer's credentials to the network, similar to Local System, but still lacks the fine-grained, automatically managed identity needed for multiple services.
- B. The Local Service account has very limited privileges on the local computer and presents anonymous credentials to the network, unsuitable for accessing network resources with specific identities.
- D. The Local System account has extensive privileges on the local computer and presents the computer's credentials to the network, but it lacks unique identity and automatic password management for specific services across multiple servers.
Group Managed Service Account (gMSA)
A type of managed service account in Active Directory that provides automatic password management, simplified SPN management, and the ability to delegate management to other administrators, used for services running on one or more servers.
- Automatic password rotation
- Simplified Service Principal Name (SPN) management
- Allows services to run on multiple hosts with unique identity
Memory trick: gMSA Grants Managed Service Access Automatically.