A city finds Print Spooler-related remote capabilities still enabled on domain controllers contrary to hardening guidance. How should that be framed?
Select an answer to reveal the explanation.
Short Explanation
Domain controllers should travel light — every extra service is another door on the vault. Spooler-style roles on DCs have a history of widening that door. Strip optional services; leave identity work to the DC.
Full Explanation
Hardening guidance generally recommends removing or disabling unnecessary roles on domain controllers to shrink remote attack surface. Print Spooler-related remote functionality on DCs is a classic example of optional exposure that does not belong on identity hosts. Print performance myths and GPO dependency claims do not justify leaving risky services enabled. Report unnecessary DC services as hardening findings.