nerdexam
CompTIA

SY0-501 · Question #53

During a routine audit, it is discovered that someone has been using a stale administrator account to log into a seldom used server. The person has been using the server to view inappropriate…

The correct answer is D. Account expiration policy. To prevent misuse of a stale administrator account, an account expiration policy is the most effective technical control, as it ensures inactive accounts are automatically disabled.

Submitted by deeparc· Mar 4, 2026Security operations

Question

During a routine audit, it is discovered that someone has been using a stale administrator account to log into a seldom used server. The person has been using the server to view inappropriate websites that are prohibited to end users. Which of the following could best prevent this from occurring again?

Options

  • ACredential management
  • BGroup policy management
  • CAcceptable use policy
  • DAccount expiration policy

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    84% (27)

Why each option

To prevent misuse of a stale administrator account, an account expiration policy is the most effective technical control, as it ensures inactive accounts are automatically disabled.

ACredential management

Credential management focuses on protecting active credentials and their secure handling, but it does not specifically prevent a stale account from remaining active and being misused.

BGroup policy management

Group Policy Management is a tool used to configure various settings, including account policies, but it is not the specific preventative policy itself that directly addresses account staleness.

CAcceptable use policy

An acceptable use policy defines expected behavior and outlines prohibitions, but it is a governance control that does not technically prevent an active, stale account from being exploited.

DAccount expiration policyCorrect

An account expiration policy directly addresses the problem of a 'stale administrator account' by ensuring that user accounts are automatically deactivated or deleted after a specified period or when they are no longer needed. This preventative measure eliminates the risk of inactive accounts remaining active and being exploited by unauthorized individuals, thereby preventing their misuse.

Concept tested: Account lifecycle management and expiration policies

Source: https://learn.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-account-expiration

Topics

#account management#stale accounts#account expiration#privilege management

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice