220-1102 · Question #143
A systems administrator needs to reset a user's password because the user forgot it. The systems administrator creates the new password and wants to further protect the user's account. Which of the…
The correct answer is A. Require the user to change the password at the next log-in. After resetting a user's password, requiring a change at the next login ensures the user sets a strong, private password and reduces the window of exposure for the administrator-set password.
Question
A systems administrator needs to reset a user's password because the user forgot it. The systems administrator creates the new password and wants to further protect the user's account. Which of the following should the systems administrator do?
Options
- ARequire the user to change the password at the next log-in
- BDisallow the user from changing the password.
- CDisable the account.
- DChoose a password that never expires.
How the community answered
(14 responses)- A86% (12)
- B7% (1)
- D7% (1)
Why each option
After resetting a user's password, requiring a change at the next login ensures the user sets a strong, private password and reduces the window of exposure for the administrator-set password.
Requiring the user to change the password at the next login ensures that only the user knows their final password, preventing the administrator from knowing the long-term password and improving the account's security posture. This practice minimizes the risk of the temporary password being misused.
Disallowing the user from changing their password would prevent them from securing their own account and contradict best security practices.
Disabling the account would prevent the user from accessing resources, which is not the goal when merely assisting with a forgotten password.
Choosing a password that never expires is a poor security practice, as it increases the risk of the password being compromised over time without a mandatory refresh.
Concept tested: Password management best practices, account security
Source: learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/password-policy
Topics
Community Discussion
No community discussion yet for this question.