nerdexam
CompTIA

SY0-301 · Question #571

A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he is prompted to…

The correct answer is C. Ann's user account was not added to the group policy. The group policy password expiration applies only to accounts added to that policy. Ann was not prompted because her account was excluded from the policy scope.

Security operations

Question

A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he is prompted to change his password; when Ann logs into the network, she is not prompted to change her password. Which of the following BEST explains why Ann is not required to change her password?

Options

  • AAnn's user account has administrator privileges.
  • BJoe's user account was not added to the group policy.
  • CAnn's user account was not added to the group policy.
  • DJoe's user account was inadvertently disabled and must be re-created.

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    15% (7)
  • C
    74% (34)
  • D
    7% (3)

Why each option

The group policy password expiration applies only to accounts added to that policy. Ann was not prompted because her account was excluded from the policy scope.

AAnn's user account has administrator privileges.

Administrator privileges do not exempt a user from password expiration policies unless a specific 'password never expires' flag is set on the account.

BJoe's user account was not added to the group policy.

The question describes Joe being prompted, which confirms his account is correctly subject to the group policy - not excluded from it.

CAnn's user account was not added to the group policy.Correct

Group Policy Objects (GPOs) apply only to the users and computers within their assigned scope. Because Ann was not added to the group policy, the 15-day password expiration rule does not apply to her account, so no prompt is triggered at login. Joe, being in the policy, is correctly prompted after 16 days.

DJoe's user account was inadvertently disabled and must be re-created.

A disabled account cannot be logged into at all; the scenario states Joe successfully logs in and is prompted, so his account is active.

Concept tested: Group Policy Object scope and password expiration

Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview

Topics

#group policy#password policy#account management#access control

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice