A security team is configuring password policies for a Windows Active Directory domain. They need to enforce a setting that prevents users from reusing any of their last 24 passwords. Which password policy setting should they configure?
Enforce password history determines how many unique new passwords must be used before an old password can be reused. Setting it to 24 prevents reuse of the last 24 passwords, directly meeting the requirement. This is the correct setting because it specifically tracks and blocks previous password hashes, ensuring users cannot cycle back to recent passwords.
Why this answer
The Enforce password history policy setting in Active Directory allows administrators to specify the number of previous passwords that cannot be reused. Setting it to 24 ensures users must choose 24 unique passwords before they can reuse an old one. This directly addresses the requirement to prevent reuse of the last 24 passwords.
Other settings like maximum age, minimum age, or complexity do not track password reuse and therefore do not meet the stated goal.
Exam trap
The trap here is confusing password history with password complexity or age policies, which do not prevent reuse of previous passwords.