Memory hook: Protect credentials; narrow privilege; verify enforcement.
Must remember
- Apply supported security baselines through Group Policy or OSConfig and validate effective settings. Exploit protection, SmartScreen and application control address different execution risks.
- Credential Guard isolates supported credential material; Windows LAPS manages local administrator passwords. Neither grants a reason to use domain administrator credentials for everyday tasks.
- Defender for Servers and endpoint protection require supported onboarding and configuration. Windows Firewall and connection security/IPsec rules control host traffic and authentication requirements.
- Secure AD with appropriate password policies, Entra Password Protection for AD DS, protected-user controls and restricted administrative delegation. Fine-grained password policies and ordinary GPO password settings have different scope semantics.
- Harden domain controllers, limit interactive/remote access, protect privileged groups and use secure administrative workstations/processes. Audit changes to delegation and privileged membership.
- Understand Kerberos versus NTLM and restrict legacy authentication through a tested migration. Authentication hardening can break dependencies; identify and remediate them before broad enforcement.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Local administrator passwords are reused across servers | Windows LAPS with controlled retrieval and rotation. |
| Only approved code should execute | A tested application-control policy, staged before enforcement. |
Traps
- A baseline configured in policy is not proof it applied successfully.
- Blanket denial of a legacy protocol without dependency discovery can cause an outage.
Active recall
1. What does Credential Guard protect?
Supported credential material through virtualization-based isolation.
2. Why limit AD delegation?
Delegated rights can create privilege-escalation paths beyond the intended task.
3. How safely deploy application control?
Test/audit representative workloads, refine policy and then enforce in stages.
4. What should be audited on privileged groups?
Membership and permission changes, their actor and justification.
5. Why protect domain controllers more strongly?
Compromise can undermine authentication and authorization across the domain.