Courseiva
mediumMultiple Choice

SSCP Practice Question: A security administrator needs to ensure that…

A security administrator needs to ensure that only authorized personnel can reset user passwords in Active Directory. Which of the following is the BEST method to delegate this responsibility without granting unnecessary privileges?

⚠ Common exam trap

Watch out — candidates often assume built-in groups like Account Operators are the simplest delegation method, overlooking that they grant far more permissions than the specific task requires, which is a common violation of the principle of least privilege tested on the SSCP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Delegation of Control wizard to assign the 'Reset user passwords and force password change at next logon' permission.

The Delegation of Control wizard allows granular assignment of specific Active Directory permissions, such as 'Reset user passwords and force password change at next logon', without granting broader administrative rights. This follows the principle of least privilege by limiting the delegated personnel to only the necessary task. Option C is correct because it directly addresses the requirement with a built-in, secure delegation mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the personnel in the Account Operators group.

    Why it's wrong here

    Account Operators can create, modify and delete most accounts and groups domain-wide, exceeding the password-reset-only requirement. It is tempting because the name suggests limited account management, and it would fit roles needing broad account lifecycle administration.

  • ✗

    Add the personnel to the Domain Admins group.

    Why it's wrong here

    Domain Admins grants full forest-wide administrative control, far beyond password reset, violating least privilege. It is tempting because Domain Admins is the obvious group for broad directory administration, and would be correct for administrators needing complete control of the domain.

  • ✓

    Use Delegation of Control wizard to assign the 'Reset user passwords and force password change at next logon' permission.

    Why this is correct

    The Delegation of Control wizard grants only the 'Reset user passwords and force password change at next logon' permission on the target organisational unit, avoiding broader rights such as Account Operators or Domain Admin that would violate least privilege.

  • ✗

    Give the personnel physical access to the domain controller.

    Why it's wrong here

    Physical access to a domain controller grants unrestricted control of Active Directory data and configuration, not scoped password reset rights. It is tempting because hands-on console access appears to bypass permission complexity, and suits isolated recovery scenarios rather than delegated administration.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.