SY0-501 · Question #51
A security administrator has been tasked with improving the overall security posture related to desktop machines on the network. An auditor has recently that several machines with confidential…
The correct answer is C. Enable group policy based screensaver timeouts. The security administrator needs to implement a technical control to prevent unauthorized viewing of confidential data on unattended desktop machines. Enabling group policy-based screensaver timeouts directly addresses this by automatically securing the display after inactivity.
Question
A security administrator has been tasked with improving the overall security posture related to desktop machines on the network. An auditor has recently that several machines with confidential customer information displayed in the screens are left unattended during the course of the day. Which of the following could the security administrator implement to reduce the risk associated with the finding?
Options
- AImplement a clean desk policy
- BSecurity training to prevent shoulder surfing
- CEnable group policy based screensaver timeouts
- DInstall privacy screens on monitors
How the community answered
(16 responses)- A6% (1)
- B6% (1)
- C75% (12)
- D13% (2)
Why each option
The security administrator needs to implement a technical control to prevent unauthorized viewing of confidential data on unattended desktop machines. Enabling group policy-based screensaver timeouts directly addresses this by automatically securing the display after inactivity.
Implementing a clean desk policy is an administrative control that addresses physical documents and items on a desk, but it does not technically secure digital information displayed on an active or unattended screen.
Security training to prevent shoulder surfing aims to educate users about protecting their screens while actively working, but it does not provide an automated mechanism to secure a screen that is left unattended.
Enabling group policy-based screensaver timeouts automates the locking or obscuring of a desktop screen after a predetermined period of inactivity. This configuration, enforced through Group Policy, directly prevents unauthorized individuals from viewing confidential customer information displayed on an unattended computer, thereby mitigating the identified risk.
Installing privacy screens on monitors restricts viewing angles for casual observers, but it does not lock the workstation or prevent someone directly in front of an unattended machine from viewing confidential information.
Concept tested: Configuring workstation screensaver lock via Group Policy
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/security-baselines/security-baselines-faq#how-do-i-configure-screen-saver-using-group-policy
Topics
Community Discussion
No community discussion yet for this question.