A program manager wants to ensure contract employees can only access the company's computers Monday through Friday from 9 a m. to 5 p.m. Which of the following would best enforce this access control?
Choose an answer
Tap an option to check your answer.
Correct answer: Creating a GPO for all contract employees and setting time-of-day log-in restrictions.
Why this is the answer
Creating a Group Policy Object (GPO) with time-of-day log-in restrictions directly addresses the requirement to limit access for contract employees to specific hours (Monday through Friday, 9 a.m. to 5 p.m.). GPOs are a powerful feature in Windows environments for centrally managing user and computer settings, including logon hours. Discretionary access control (DAC) focuses on object owners determining permissions, which doesn't directly enforce time-based access for groups. OAuth is an authorization framework typically used for delegated access to resources, not for enforcing local login time restrictions. SAML with federation is an authentication standard for single sign-on across different security domains; while it handles authentication, it doesn't inherently manage time-based access restrictions on the local network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed