A city workstation fleet has extremely permissive UAC settings. How should the tester include that posture in Windows risk framing?
Select an answer to reveal the explanation.
Short Explanation
UAC is the "are you sure?" prompt before climbing the privilege ladder. Crank it down too far and elevation gets easier for whoever already has a foothold. Call weak UAC an enabling gap, not a free Domain Admin card.
Full Explanation
User Account Control mediates many elevation prompts and integrity transitions on Windows. Extremely permissive configurations lower the friction of privilege-escalation paths that still require an underlying technique or admin-capable context. UAC is a Windows control, not a macOS Gatekeeper substitute, and it does not eliminate the need for sound local admin credential hygiene. Include UAC posture in host risk framing and remediation advice.