Lab — Create, Link, and Harden a Group Policy Object

SY0-701 · 4.5 Group Policy Endpoint hardening

Larkspur Analytics is onboarding a wave of seasonal contractors into its Engineering and Logistics teams, and the front Reception area runs shared kiosk PCs. Security has approved a hardened endpoint configuration and exported it to the security template endpoint_hardening.inf (stored in C:\SecBaselines on the domain controller LARK-DC1).

You are the security administrator. From the Group Policy Management console on the larkspur.local domain, complete the following:

  1. Create a GPO named Endpoint Hardening Baseline in the larkspur.local domain.
  2. Link that GPO to three locations: Engineering › Seasonal-Engineering, Logistics › Seasonal-Logistics, and Reception.
  3. Import the endpoint_hardening.inf template into the GPO's Security Settings.
Group Policy Management — LARK-DC1 larkspur.local

Group Policy Management

Select an item in the tree, then open its action menu (right-click, the ⋮ button, or press the menu key).
Tip: right-click Group Policy Objects to create a new GPO, right-click an OU to link a GPO, and right-click a GPO then choose Edit to import a security template.

Task checklist

    Knowledge check

    Score 0 / 8

    © 2026 [LAB AUTHOR]. Original instructional simulation for CompTIA Security+ SY0-701 objective 4.5 (Group Policy). Not affiliated with any courseware vendor. Replace this notice with your own before distribution.