SY0-301 · Question #137
Sara, a security manager, has decided to force expiration of all company passwords by the close of business day. Which of the following BEST supports this reasoning?
The correct answer is A. A recent security breach in which passwords were cracked. Forcing immediate password expiration company-wide is a reactive measure most consistent with responding to a security breach where passwords were compromised. No other listed option provides an urgent, breach-driven rationale for end-of-day expiration.
Question
Sara, a security manager, has decided to force expiration of all company passwords by the close of business day. Which of the following BEST supports this reasoning?
Options
- AA recent security breach in which passwords were cracked.
- BImplementation of configuration management processes.
- CEnforcement of password complexity requirements.
- DImplementation of account lockout procedures.
How the community answered
(35 responses)- A86% (30)
- B9% (3)
- C3% (1)
- D3% (1)
Why each option
Forcing immediate password expiration company-wide is a reactive measure most consistent with responding to a security breach where passwords were compromised. No other listed option provides an urgent, breach-driven rationale for end-of-day expiration.
A recent breach where passwords were cracked means attackers may already possess valid credentials, making immediate forced expiration essential to revoke any stolen passwords before they can be used further. This is the only scenario among the options that justifies the urgency and scope of forcing all passwords to expire by end of business day.
Configuration management processes involve maintaining known-good system states and do not necessitate emergency password expiration across all accounts.
Password complexity requirements define the rules for creating passwords but do not by themselves trigger a need for immediate forced expiration of all existing passwords.
Account lockout procedures lock accounts after failed login attempts and are a preventive control, not a reason to expire all passwords immediately.
Concept tested: Incident response - forced password expiration after breach
Source: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-password-ban-bad
Topics
Community Discussion
No community discussion yet for this question.