Confirming the Configuration

Service configuration is an extremely important security concern. An important security tenet is to reduce the attack surface. One reason why Windows Server 2008 Core edition (Server Core) is so popular is due to its reduced attack surface. Because service configuration is so important to reducing the attack surface, you must ask yourself these three important configuration questions:

  • How is the service set to start (automatically, manually, disabled)?

  • What account does it start under (local system, network service, local service, user-defined)?

  • What password is used for the service (automatic, user-defined)?

Get Windows PowerShell™ Scripting Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.