CompTIA Security+ (SY0-701)Security OperationsMedium
A security analyst is configuring account protections to stop brute-force password guessing. The analyst wants locked-out accounts to automatically become usable again after a set period, without requiring users to call the help desk. Which policy setting accomplishes this?
- APassword complexity requirement
- BPassword history
- CMinimum password age
- DAccount lockout duration
Show answer & explanationAnswer & explanation
Correct answer: D. Account lockout duration
Account lockout duration specifies how long an account remains locked after exceeding the failed-attempt threshold before it automatically re-enables, balancing security with usability. Complexity, history, and minimum age govern password composition and reuse, not automatic re-enablement after lockout.
Why the other options are wrong
- A. Controls character requirements for passwords, not lockout recovery.
- B. Prevents reuse of previous passwords, unrelated to lockout timing.
- C. Prevents changing a password too soon after setting it, unrelated to lockout.
Account Lockout Duration
The length of time an account stays locked after exceeding the allowed number of failed login attempts before it automatically unlocks.
- Works with lockout threshold (max failed attempts)
- Reduces brute-force success without permanent lockout
- Balances security with user convenience
Memory trick: Think of a timed vault door: it locks after too many wrong tries and reopens itself after the timer runs out.