CompTIA A+ Core 2 (220-1202)Software TroubleshootingMedium
A network administrator configures domain user accounts to automatically lock for 30 minutes after five consecutive incorrect password attempts. Which security concept does this configuration implement?
- AScreen lock timeout
- BAccount lockout policy
- CPassword complexity requirements
- DMultifactor authentication
Show answer & explanationAnswer & explanation
Correct answer: B. Account lockout policy
An account lockout policy locks an account after a defined number of failed login attempts, mitigating brute-force password guessing attacks. Password complexity and MFA are separate controls, and screen lock timeout addresses idle device exposure, not repeated failed logins.
Why the other options are wrong
- A. Controls when an idle screen locks, not failed login handling.
- C. Governs password structure (length/characters), not lockout after failed attempts.
- D. MFA adds a second verification factor, unrelated to lockout thresholds.
Account Lockout Policy
A security setting that disables sign-in to an account for a period (or until admin reset) after a specified number of consecutive failed password attempts, mitigating brute-force attacks.
- Configured via Group Policy on domains
- Includes lockout threshold and duration
- Reduces effectiveness of automated password guessing
Memory trick: 'Five strikes, you're locked out' — the lockout bouncer.