nerdexam
CompTIA

220-1102 · Question #143

A systems administrator needs to reset a user's password because the user forgot it. The systems administrator creates the new password and wants to further protect the user's account. Which of the…

The correct answer is A. Require the user to change the password at the next log-in. After resetting a user's password, requiring a change at the next login ensures the user sets a strong, private password and reduces the window of exposure for the administrator-set password.

Security

Question

A systems administrator needs to reset a user's password because the user forgot it. The systems administrator creates the new password and wants to further protect the user's account. Which of the following should the systems administrator do?

Options

  • ARequire the user to change the password at the next log-in
  • BDisallow the user from changing the password.
  • CDisable the account.
  • DChoose a password that never expires.

How the community answered

(14 responses)
  • A
    86% (12)
  • B
    7% (1)
  • D
    7% (1)

Why each option

After resetting a user's password, requiring a change at the next login ensures the user sets a strong, private password and reduces the window of exposure for the administrator-set password.

ARequire the user to change the password at the next log-inCorrect

Requiring the user to change the password at the next login ensures that only the user knows their final password, preventing the administrator from knowing the long-term password and improving the account's security posture. This practice minimizes the risk of the temporary password being misused.

BDisallow the user from changing the password.

Disallowing the user from changing their password would prevent them from securing their own account and contradict best security practices.

CDisable the account.

Disabling the account would prevent the user from accessing resources, which is not the goal when merely assisting with a forgotten password.

DChoose a password that never expires.

Choosing a password that never expires is a poor security practice, as it increases the risk of the password being compromised over time without a mandatory refresh.

Concept tested: Password management best practices, account security

Source: learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/password-policy

Topics

#Password management#Account security#Administrative best practices#User account control

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice