A systems administrator is configuring local security policies on standalone Windows workstations designated for short-term contractors at a financial services firm. To minimize the attack surface associated with default credential exploitation and unauthenticated local access, which of the following workstation hardening actions should the technician perform?
- Disable the built-in Guest account and rename the default Administrator account.Cevap
- BUse Event Viewer to schedule daily clearing of the system log to reduce disk usage.
- CModify Credential Manager to grant standard user accounts automatic administrative privileges without elevation prompts.
- DAttach privacy screen filters to monitors to prevent unauthorized account credential modifications.
Cevap
Disabling the built-in Guest account and renaming the default Administrator account is the best practice for local account hardening.
Disabling the built-in Guest account and renaming the default Administrator account reduces the workstation's attack surface by eliminating default entry points that attackers frequently target in automated brute-force attacks.
Adım Adım Çözüm
Anahtar Kavram
Workstation Account Hardening and Default Account Management