A security technician is configuring local group policies for corporate laptops issued to field auditors who frequently operate in untrusted, public environments. The technician must reduce the attack surface against unauthorized physical access when unattended and mitigate brute-force risks against default local credentials. Which of the following workstation hardening measures should the technician implement to meet these security requirements? (Select TWO.)
- Configure an screen saver lockout policy that requires password re-authentication after a short period of inactivityAnswer
- Disable the local Guest account and rename the default local Administrator accountAnswer
- CUse Event Viewer in Computer Management to dynamically block unauthorized incoming network ports in real time
- DConfigure monitor privacy filter angles through the System applet in Control Panel to prevent hardware theft
Answer
The correct hardening measures are configuring an inactive screen saver lockout requiring password re-authentication, and disabling the local Guest account while renaming the default Administrator account.
Implementing an inactivity screen saver lock requiring password re-authentication protects unattended endpoints from physical access. Disabling the default Guest account and renaming the default local Administrator account minimizes local account exploitation risks.
Step-by-Step Solution
Key Concept
Workstation Hardening via Account Management and Inactivity Lockout Policies