Soru

Zorluk: OrtaWindows Security Settings and User Account Control

A desktop administrator is configuring Local Security Policy and User Account Control (UAC) settings on standalone Windows 11 Pro workstations to harden end-user systems. Which TWO configuration settings or UAC behaviors accurately describe proper administrative enforcement in this environment? (Select TWO.)

  1. Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' prevents standard users from receiving a credential prompt when attempting administrative tasks.Cevap
  2. Enabling 'User Account Control: Switch to the secure desktop when prompting for elevation' isolates the prompt by dimming the desktop and preventing software-based interaction from unprivileged processes.Cevap
  3. C
    Using the Local Security Policy snap-in (secpol.msc) allows administrators to deploy these UAC security policies identically across Windows 11 Home edition computers.
  4. D
    Disabling User Account Control completely removes local NTFS permissions from system directories, overriding local file access restrictions for standard user accounts.

Cevap

The two correct answers are: setting the standard user elevation behavior policy to automatically deny requests, and enabling the secure desktop feature for elevation prompts.
Configuring the elevation prompt behavior for standard users to automatically deny elevation requests strictly enforces least privilege by blocking credential prompts for non-admin users. Additionally, enforcing the Secure Desktop for elevation prompts isolates the UAC dialog on a separate visual desktop layer, preventing malicious software from capturing or injecting user input during elevation.

Adım Adım Çözüm

1
Analyze standard user elevation policies in Local Security Policy
Configuring UAC to 'Automatically deny elevation requests' ensures standard users cannot enter administrator credentials to elevate permissions.
This policy enforces strict least privilege by preventing standard accounts from initiating privilege escalation.
2
Evaluate Secure Desktop isolation settings
Enabling 'Switch to the secure desktop when prompting for elevation' runs prompts in an isolated desktop context.
Secure Desktop prevents malware or background applications from sending fake clicks or keystrokes to elevate privileges.

Anahtar Kavram

Windows User Account Control and Local Security Policy configuration
Bu soruyu puanla