mediumMultiple ChoiceObjective-mapped
220-1202 Practice Question: During a security audit, you find that several…
During a security audit, you find that several employees have been using the same weak password for their domain accounts. Which remediation should you implement first?
⚠ Common exam trap
CompTIA often tests the distinction between administrative controls (like emails or account disabling) and technical controls (like Group Policy), where candidates mistakenly choose a non-technical, awareness-based option (C) over a policy-enforced technical solution (B).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a password policy in Group Policy requiring complexity and minimum length
The most effective first step to prevent weak passwords is to enforce a strong password policy via Group Policy. This centrally mandates complexity requirements (e.g., uppercase, lowercase, digits, special characters) and a minimum length (typically 8–14 characters), which directly blocks the use of simple, common passwords at the domain level. Unlike awareness campaigns or reactive measures, this technical control proactively enforces security standards across all domain accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user accounts and require a manager to re-enable them
Why it's wrong here
Disabling user accounts immediately halts user productivity, causing significant operational disruption and requiring manual intervention for re-enablement. While it prevents immediate access, this is a reactive measure that fails to implement a proactive, systemic solution for password strength, merely shifting the burden of re-enabling without enforcing better password creation practices for the future.
- ✓
Configure a password policy in Group Policy requiring complexity and minimum length
Why this is correct
Implementing a password policy via Group Policy Objects (GPOs) centrally enforces security requirements across all domain-joined user accounts. This technical control mandates specific criteria, such as minimum length, character complexity (e.g., uppercase, lowercase, numbers, symbols), and password history, ensuring that users create and maintain strong, unique passwords consistently throughout the organization, preventing future weak password usage.
- ✗
Send a company-wide email reminding users to choose strong passwords
Why it's wrong here
While user education is a valuable component of a comprehensive security strategy, a company-wide email serves only as a reminder and lacks any technical enforcement mechanism. Employees can easily disregard such advisories, continuing to use weak or easily guessable passwords, thus leaving the organization vulnerable to credential-based attacks without any actual policy implementation or technical control.
- ✗
Install a third-party password manager for all employees
Why it's wrong here
A third-party password manager helps users generate and store strong, unique passwords for various applications and websites. However, it does not directly enforce password policies for the *domain user accounts* themselves, which are managed by the Active Directory environment. While beneficial for individual password hygiene, it doesn't provide the centralized, mandatory control needed to secure the primary network login credentials across the entire domain.
Go deeper
Related to this question
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.