CompTIA SecurityX (CAS-005)Security EngineeringHard

A security engineer is hardening a Windows Server that hosts a critical enterprise application. The application runs as a service and requires specific permissions to access network resources and file shares on other machines within the domain, but without requiring a user password for the service account itself. The organization wants to centralize management of these service accounts and their associated Service Principal Names (SPNs) in Active Directory, reducing the risk of password sprawl and simplifying credential rotation. Which type of service account is BEST suited for this scenario?

  1. ANetwork Service Account
  2. BLocal User Account
  3. CGroup Managed Service Account (gMSA)
  4. DLocal System Account
Show answer & explanation

Correct answer: C. Group Managed Service Account (gMSA)

Group Managed Service Accounts (gMSAs) are Windows service accounts designed for use by services on multiple servers. They automatically manage passwords, simplify SPN management, and can be used on multiple hosts, eliminating the need for manual password rotation and reducing the risk of credential compromise. They are ideal for distributed applications that need to access network resources without interactive logon.

Why the other options are wrong

  • A. Network Service Account presents the computer's credentials to the network, not a specific service identity, and does not support automatic password management or SPN registration for service accounts.
  • B. Local User Accounts are not designed for services, require manual password management, and are not suitable for accessing network resources as a service identity.
  • D. Local System Account has extensive privileges on the local machine and cannot access network resources as a specific identity without credential delegation, which poses security risks.

Group Managed Service Account (gMSA)

A type of Windows service account that provides automatic password management, simplified SPN management, and the ability to be used across multiple servers in a domain.

  • Automatic password rotation and management by Active Directory
  • Simplifies Service Principal Name (SPN) management
  • Can be used by multiple hosts in a domain
  • Eliminates need for manual password changes for service accounts

Memory trick: gMSA: Group Many Service Accounts.

More Security Engineering questions