Courseiva
mediumMultiple ChoiceObjective-mapped

220-1202 Practice Question: During a security audit, you find that several…

During a security audit, you find that several employees have been using the same weak password for their domain accounts. Which remediation should you implement first?

⚠ Common exam trap

CompTIA often tests the distinction between administrative controls (like emails or account disabling) and technical controls (like Group Policy), where candidates mistakenly choose a non-technical, awareness-based option (C) over a policy-enforced technical solution (B).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a password policy in Group Policy requiring complexity and minimum length

The most effective first step to prevent weak passwords is to enforce a strong password policy via Group Policy. This centrally mandates complexity requirements (e.g., uppercase, lowercase, digits, special characters) and a minimum length (typically 8–14 characters), which directly blocks the use of simple, common passwords at the domain level. Unlike awareness campaigns or reactive measures, this technical control proactively enforces security standards across all domain accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable the user accounts and require a manager to re-enable them

    Why it's wrong here

    Disabling user accounts immediately halts user productivity, causing significant operational disruption and requiring manual intervention for re-enablement. While it prevents immediate access, this is a reactive measure that fails to implement a proactive, systemic solution for password strength, merely shifting the burden of re-enabling without enforcing better password creation practices for the future.

  • Configure a password policy in Group Policy requiring complexity and minimum length

    Why this is correct

    Implementing a password policy via Group Policy Objects (GPOs) centrally enforces security requirements across all domain-joined user accounts. This technical control mandates specific criteria, such as minimum length, character complexity (e.g., uppercase, lowercase, numbers, symbols), and password history, ensuring that users create and maintain strong, unique passwords consistently throughout the organization, preventing future weak password usage.

  • Send a company-wide email reminding users to choose strong passwords

    Why it's wrong here

    While user education is a valuable component of a comprehensive security strategy, a company-wide email serves only as a reminder and lacks any technical enforcement mechanism. Employees can easily disregard such advisories, continuing to use weak or easily guessable passwords, thus leaving the organization vulnerable to credential-based attacks without any actual policy implementation or technical control.

  • Install a third-party password manager for all employees

    Why it's wrong here

    A third-party password manager helps users generate and store strong, unique passwords for various applications and websites. However, it does not directly enforce password policies for the *domain user accounts* themselves, which are managed by the Active Directory environment. While beneficial for individual password hygiene, it doesn't provide the centralized, mandatory control needed to secure the primary network login credentials across the entire domain.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.