050-696 · Question #147
Your company has four regional offices. You are the overall administrator for the entire organization. Each regional office has its own network administrator. You allow yourself and each regional admi
The correct answer is E. No, each container administrator should have their own user object with specific rights assigned.. Novell security best practices prohibit sharing the built-in Admin object among multiple administrators; each administrator must have a dedicated user object with only the rights required for their specific scope.
Question
Options
- AYes, all Novell security recommendations have been met.
- BNo, you shouldn't allow users objects to have grace logins.
- CNo, you shouldn't assign user accounts to temporary employees.
- DNo, you shouldn't use multiple network administrators for the same tree.
- ENo, each container administrator should have their own user object with specific rights assigned.
How the community answered
(65 responses)- A6% (4)
- B2% (1)
- C12% (8)
- D3% (2)
- E77% (50)
Why each option
Novell security best practices prohibit sharing the built-in Admin object among multiple administrators; each administrator must have a dedicated user object with only the rights required for their specific scope.
All recommendations have not been met because the Admin object is being shared across multiple individuals, violating the principle of individual accountability.
Grace logins are a configurable and acceptable security feature; Novell does not universally recommend disabling them.
Assigning accounts with expiration dates to temporary employees is consistent with Novell security recommendations, not a violation.
Delegating administration to multiple regional administrators is an accepted and recommended practice for large, distributed eDirectory trees.
Sharing a single Admin account eliminates individual accountability, prevents meaningful auditing, and grants every administrator full rights across the entire tree regardless of their actual scope of responsibility. Novell recommends creating separate user objects for each administrator and assigning only the rights needed for that person's container or organizational unit. This principle of least privilege limits the damage from compromised credentials and provides a clear audit trail for each administrator's actions.
Concept tested: Novell eDirectory administrative account delegation best practices
Source: https://www.novell.com/documentation/edir88/edir88/data/a2iii88.html
Topics
Community Discussion
No community discussion yet for this question.