Level 1, Not Scorable Avoid installing SQL Server on a domain controller. If SQL Server were installed on a domain controller, a successful attack against the database could potentially compromise all domain resources. ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 32.