SY0-301 · Question #571
A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he is prompted to…
The correct answer is C. Ann's user account was not added to the group policy. The group policy password expiration applies only to accounts added to that policy. Ann was not prompted because her account was excluded from the policy scope.
Question
A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he is prompted to change his password; when Ann logs into the network, she is not prompted to change her password. Which of the following BEST explains why Ann is not required to change her password?
Options
- AAnn's user account has administrator privileges.
- BJoe's user account was not added to the group policy.
- CAnn's user account was not added to the group policy.
- DJoe's user account was inadvertently disabled and must be re-created.
How the community answered
(46 responses)- A4% (2)
- B15% (7)
- C74% (34)
- D7% (3)
Why each option
The group policy password expiration applies only to accounts added to that policy. Ann was not prompted because her account was excluded from the policy scope.
Administrator privileges do not exempt a user from password expiration policies unless a specific 'password never expires' flag is set on the account.
The question describes Joe being prompted, which confirms his account is correctly subject to the group policy - not excluded from it.
Group Policy Objects (GPOs) apply only to the users and computers within their assigned scope. Because Ann was not added to the group policy, the 15-day password expiration rule does not apply to her account, so no prompt is triggered at login. Joe, being in the policy, is correctly prompted after 16 days.
A disabled account cannot be logged into at all; the scenario states Joe successfully logs in and is prompted, so his account is active.
Concept tested: Group Policy Object scope and password expiration
Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview
Topics
Community Discussion
No community discussion yet for this question.