A library workstation exposes an unnecessary elevated local service related to printer spooler-class functionality. Without providing exploit steps, what is the sound assessment takeaway?
Select an answer to reveal the explanation.
Short Explanation
Extra elevated services are extra doors into the house—especially on a plain workstation that does not need them. Spotting risky local services is part of Windows priv-esc awareness, not a demand for a public exploit write-up. Shrink the surface; do not ignore it.
Full Explanation
Local services running with high privileges expand the Windows attack surface, including historically sensitive components such as print spooler-related services when left enabled where unnecessary. Assessors should identify and question elevated services during enumeration without needing payload detail in conceptual findings. Risk is not uniform across all services, and many issues are local rather than Internet-only. RoE rarely forbids service enumeration itself; it constrains how impact is demonstrated.