SY0-501 · Question #397
A security manager is creating an account management policy for a global organization with sales personnel who must access corporate network resources while traveling all over the world. Which of…
The correct answer is B. Password complexity C. Location-based authentication. For traveling sales personnel accessing corporate resources globally, the policy must address strong authentication and adaptive access controls that account for the user's physical location.
Question
A security manager is creating an account management policy for a global organization with sales personnel who must access corporate network resources while traveling all over the world. Which of the following practices is the security manager MOST likely to enforce with the policy? (Select TWO)
Options
- ATime-of-day restrictions
- BPassword complexity
- CLocation-based authentication
- DGroup-based access control
- EStandard naming convention
How the community answered
(39 responses)- A5% (2)
- B79% (31)
- D3% (1)
- E13% (5)
Why each option
For traveling sales personnel accessing corporate resources globally, the policy must address strong authentication and adaptive access controls that account for the user's physical location.
Time-of-day restrictions would block traveling sales personnel from accessing resources outside of defined hours, which is impractical for a global workforce operating across multiple time zones.
Password complexity is a fundamental account management control that ensures credentials are resistant to brute-force and dictionary attacks, which is critical when users authenticate from diverse, potentially untrusted networks worldwide.
Location-based authentication restricts or challenges access attempts based on the user's geographic location, allowing the organization to flag or block logins from unexpected countries while still permitting legitimate travel-related access through adaptive policies.
Group-based access control governs what resources users can access based on their role, but it does not directly address the account management challenges specific to traveling users authenticating from worldwide locations.
Standard naming conventions are an administrative best practice for account organization and auditing but do not provide any authentication security or access control relevant to traveling personnel.
Concept tested: Account management policy for traveling global users
Source: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition
Topics
Community Discussion
No community discussion yet for this question.