CompTIA A+ Core 2 (220-1202)Software TroubleshootingMedium

A network administrator configures domain user accounts to automatically lock for 30 minutes after five consecutive incorrect password attempts. Which security concept does this configuration implement?

  1. AScreen lock timeout
  2. BAccount lockout policy
  3. CPassword complexity requirements
  4. DMultifactor authentication
Show answer & explanation

Correct answer: B. Account lockout policy

An account lockout policy locks an account after a defined number of failed login attempts, mitigating brute-force password guessing attacks. Password complexity and MFA are separate controls, and screen lock timeout addresses idle device exposure, not repeated failed logins.

Why the other options are wrong

  • A. Controls when an idle screen locks, not failed login handling.
  • C. Governs password structure (length/characters), not lockout after failed attempts.
  • D. MFA adds a second verification factor, unrelated to lockout thresholds.

Account Lockout Policy

A security setting that disables sign-in to an account for a period (or until admin reset) after a specified number of consecutive failed password attempts, mitigating brute-force attacks.

  • Configured via Group Policy on domains
  • Includes lockout threshold and duration
  • Reduces effectiveness of automated password guessing

Memory trick: 'Five strikes, you're locked out' — the lockout bouncer.

More Software Troubleshooting questions