SY0-301 · Question #766
An administrator notices that former temporary employees accounts are still active on a domain. Which of the following can be implemented to increase security and prevent this from happening?
The correct answer is B. Implement an account expiration date for temporary employees. Setting an account expiration date is a proactive control that automatically disables an account on a specified date, making it ideal for temporary or contract workers whose end dates are known in advance. This eliminates the risk of forgotten active accounts after employment…
Question
An administrator notices that former temporary employees accounts are still active on a domain. Which of the following can be implemented to increase security and prevent this from happening?
Options
- ARun a last logon script to look for inactive accounts.
- BImplement an account expiration date for temporary employees.
- CImplement a password expiration policy.
- DImplement time of day restrictions for all temporary employees.
How the community answered
(45 responses)- A7% (3)
- B89% (40)
- C2% (1)
- D2% (1)
Explanation
Setting an account expiration date is a proactive control that automatically disables an account on a specified date, making it ideal for temporary or contract workers whose end dates are known in advance. This eliminates the risk of forgotten active accounts after employment ends. Running a last logon script is a reactive detective control, not a preventive one. A password expiration policy forces periodic password changes but does not disable the account when the employee leaves. Time of day restrictions limit when someone can log in but still leave the account active and potentially accessible - they do not remove access when employment ends.
Topics
Community Discussion
No community discussion yet for this question.