A security analyst is auditing endpoint hardening configurations for shared customer service desktops. Corporate policy requires that inactive user sessions automatically lock after five minutes without terminating running applications, and that unauthenticated users cannot access local resources via legacy default accounts. Which of the following configurations best satisfies both requirements?
- Enable a password-protected screen saver with a 5-minute wait time and ensure the local Guest account is disabled.Cevap
- BSet the display power-off timer to 5 minutes and modify local user account rights using Event Viewer.
- CConfigure a 5-minute system sleep timer using Credential Manager and add the local Guest account to the local Administrators group.
- DInstall physical monitor privacy filters and leave the built-in Guest account enabled with a blank password for quick station switching.
Cevap
Enabling a password-protected screen saver set to a 5-minute timeout while disabling the built-in local Guest account.
The correct choice configures a password-protected screen saver set to trigger after 5 minutes of inactivity, which locks the active session while retaining unsaved work in open applications. Additionally, disabling the built-in local Guest account follows security best practices by eliminating an unneeded account that could otherwise be targeted for unauthorized access.
Adım Adım Çözüm
Anahtar Kavram
Workstation Hardening and Account Security Controls
Tahmini Süre:1m 30s