A penetration test reveals that an expired user account was used to authenticate to a file server three months after termination. Which AD control would have prevented this risk?
-
A
Configuring a fine-grained password policy with a maximum password age
-
B
Enabling automatic account expiration and monitoring via audit logs
-
C
Adding terminated user accounts to a Deny Logon GPO
-
D
Moving terminated accounts to a disabled OU with restricted permissions