An organization is implementing a control for the Account Monitoring and Control CIS Control, and have set the Account Lockout Policy as shown below. What is the risk presented by these settings?
I think the key here is to understand how the lockout policy interacts with password complexity and length requirements. That could be the key to identifying the main risk.
Okay, let me see. The All users group is likely used to grant access to common features and functionality that all users should have access to. I'm guessing the answer is D, Console and common features.
Once locked, accounts can't be unlocked? Wow, that's like a one-way ticket to the password graveyard. Guess the IT team will be busy resetting passwords all day.
Password length and complexity reduced? Well, that's one way to make it easier for everyone to remember their passwords. Maybe they should just use '12345' instead.
Okay, so legitimate users might get locked out? Sounds like a great way to keep them from accessing the resources they need. Productivity is overrated anyway.
Delpha
3 months agoMalinda
3 months agoAdolph
3 months agoLina
4 months agoLenna
4 months agoJannette
4 months agoEdwin
4 months agoGenevieve
4 months agoIrene
5 months agoQueen
5 months agoChauncey
5 months agoHermila
5 months agoKarol
5 months agoLigia
5 months agoDan
9 months agoCarey
9 months agoTamekia
8 months agoDaren
8 months agoKenneth
8 months agoFelicidad
9 months agoJanessa
10 months agoJesusita
10 months agoBarney
8 months agoCarey
8 months agoUlysses
9 months agoBarrie
10 months agoGail
10 months agoMirta
11 months agoHelene
10 months agoHelene
10 months agoCharlesetta
11 months ago