A transit administrator uses the same password on a personal Domain Admin account and a daily workstation login. What hygiene lesson should the report emphasize?
Select an answer to reveal the explanation.
Short Explanation
One password unlocking both the daily laptop and Domain Admin is like one key for the lobby and the vault. When the laptop falls, the vault opens too. Separate accounts and unique passwords break that reuse chain.
Full Explanation
Credential reuse across privilege tiers turns a workstation compromise into a direct path to directory control. Defenders and assessors expect dedicated privileged identities that are never used for routine mail or browsing, with passwords that do not match lower-trust accounts. MFA on unrelated apps does not neutralize reuse on the admin secret itself. CPTS-style findings should highlight separation and uniqueness as core AD hygiene, not optional polish.