Sara, a security manager, has decided to force expiration of all company passwords by the close
of business day. Which of the following BEST supports this reasoning?

A.
A recent security breach in which passwords were cracked.
B.
Implementation of configuration management processes.
C.
Enforcement of password complexity requirements.
D.
Implementation of account lockout procedures.
Explanation:
A password only needs to be changed if it doesn’t meet the compliance requirements of the
company’s password policy, or is evidently insecure. It will also need to be changed if it has been
reused, or due to possible compromise as a result of a system intrusion.
if A is the situation then force expiration should be immediate instead of waiting till the end of business day because so much damage can occur till the end of the day and every second is important in breach situation
0
0
It says “by the end of the day” which means before the end of the day. Not at the end of the day.
0
0