Soru

Zorluk: OrtaWorkstation Hardening and Best Practices

A desktop technician is implementing security hardening baseline policies on several standalone Windows workstations used by temporary contractors in a corporate office. The workstations must automatically secure active user sessions during periods of inactivity and restrict unauthorized local administrative capabilities. Which of the following security configurations best achieves these requirements?

  1. Configure a password-protected screen saver timeout after 5 minutes of inactivity and disable the built-in Guest account.Cevap
  2. B
    Enable the built-in Guest account for temporary access and configure AutoPlay to run executable installers from connected USB drives.
  3. C
    Use Event Viewer to log inactive user sessions and assign contractor accounts to the local Administrators group for access control.
  4. D
    Attach physical cable locks to the workstations and rely on privacy screen filters as the primary mechanism to prevent session hijacking.

Cevap

Configure a password-protected screen saver timeout after 5 minutes of inactivity and disable the built-in Guest account.
Enforcing a screen lock with a short inactivity timeout and requiring authentication upon resume prevents unauthorized personnel from hijacking an open session. Disabling unused built-in accounts, such as the Guest account, directly aligns with CompTIA security best practices for reducing the workstation attack surface.

Adım Adım Çözüm

1
Identify the primary security requirements for workstation hardening in the scenario.
Requirements are preventing unauthorized access to unattended active sessions and disabling unused default account attack vectors.
Hardening best practices require session lock controls and attack surface reduction.
2
Evaluate operating system security settings that enforce session protection.
Configuring a short screen lock/screensaver timeout requiring password re-entry ensures that inactive desktops lock automatically.
This mitigates unauthorized physical interaction when a user leaves their desk.
3
Evaluate local account hardening controls.
Disabling built-in accounts such as the Guest account prevents anonymous access.
Default and unneeded accounts should always be disabled to minimize local vulnerability paths.

Anahtar Kavram

Workstation Hardening Baselines and Account Hygiene
Tahmini Süre:1m 15s
Bu soruyu puanla