In an AD DS domain you must set a ticket-granting ticket (TGT) lifetime for specific user and computer accounts. The change should affect as few other accounts as possible and require minimal administrative effort. Which configuration should you apply?
Choose an answer
Tap an option to check your answer.
Correct answer: an authentication policy and an authentication policy silo.
Why this is the answer
Authentication policies and authentication policy silos are the correct choice because they allow you to define specific authentication requirements, including TGT lifetimes, for a targeted set of user and computer accounts. This method provides granular control, ensuring that only the specified accounts are affected, thus minimizing impact on other accounts. It also offers a centralized way to manage these policies, reducing administrative effort compared to applying settings individually. A dynamic access control policy is for authorization (what resources a user can access), not authentication (how a user proves their identity). A password policy defines password complexity, length, and history, not TGT lifetimes. A fine-grained password policy allows different password and account lockout policies for different users or groups, but it does not manage TGT lifetimes.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed