An audit finds batch-job service accounts for the water billing system with non-expiring passwords and interactive logon rights on jump hosts. Which remediation best hardens those accounts?
Select an answer to reveal the explanation.
Short Explanation
Service accounts are not people and should not lounge on jump boxes. Lock interactive logon, stash secrets in a vault with rotation, and keep rights skinny—non-expiring password plus Domain Admin is how outages become breaches.
Full Explanation
Service account hygiene includes denying interactive logon, storing and rotating credentials in a secrets manager or gMSA-class mechanism, and scoping rights to the specific service. Non-expiring passwords plus interactive logon expand theft and misuse risk; Domain Admin membership and personalizing service identities worsen accountability. CISSP Domain 5 expects deliberate service-account management.