nerdexam
Novell

050-696 · Question #147

Your company has four regional offices. You are the overall administrator for the entire organization. Each regional office has its own network administrator. You allow yourself and each regional admi

The correct answer is E. No, each container administrator should have their own user object with specific rights assigned.. Novell security best practices prohibit sharing the built-in Admin object among multiple administrators; each administrator must have a dedicated user object with only the rights required for their specific scope.

Novell eDirectory Management

Question

Your company has four regional offices. You are the overall administrator for the entire organization. Each regional office has its own network administrator. You allow yourself and each regional administrator to use the Admin user object to manage the eDirectory tree. You have configured each user object to require unique passwords and to limit grace logins to 3. All user objects for temporary employees have an expiration date assigned to them. Do these policies conform to Novell's security recommendations.?

Options

  • AYes, all Novell security recommendations have been met.
  • BNo, you shouldn't allow users objects to have grace logins.
  • CNo, you shouldn't assign user accounts to temporary employees.
  • DNo, you shouldn't use multiple network administrators for the same tree.
  • ENo, each container administrator should have their own user object with specific rights assigned.

How the community answered

(65 responses)
  • A
    6% (4)
  • B
    2% (1)
  • C
    12% (8)
  • D
    3% (2)
  • E
    77% (50)

Why each option

Novell security best practices prohibit sharing the built-in Admin object among multiple administrators; each administrator must have a dedicated user object with only the rights required for their specific scope.

AYes, all Novell security recommendations have been met.

All recommendations have not been met because the Admin object is being shared across multiple individuals, violating the principle of individual accountability.

BNo, you shouldn't allow users objects to have grace logins.

Grace logins are a configurable and acceptable security feature; Novell does not universally recommend disabling them.

CNo, you shouldn't assign user accounts to temporary employees.

Assigning accounts with expiration dates to temporary employees is consistent with Novell security recommendations, not a violation.

DNo, you shouldn't use multiple network administrators for the same tree.

Delegating administration to multiple regional administrators is an accepted and recommended practice for large, distributed eDirectory trees.

ENo, each container administrator should have their own user object with specific rights assigned.Correct

Sharing a single Admin account eliminates individual accountability, prevents meaningful auditing, and grants every administrator full rights across the entire tree regardless of their actual scope of responsibility. Novell recommends creating separate user objects for each administrator and assigning only the rights needed for that person's container or organizational unit. This principle of least privilege limits the damage from compromised credentials and provides a clear audit trail for each administrator's actions.

Concept tested: Novell eDirectory administrative account delegation best practices

Source: https://www.novell.com/documentation/edir88/edir88/data/a2iii88.html

Topics

#security policy#Admin user object#container administrator#Novell security recommendations

Community Discussion

No community discussion yet for this question.

Full 050-696 Practice