A transit domain configures extremely long Kerberos ticket lifetimes. What conceptual risk should the report call out?
Select an answer to reveal the explanation.
Short Explanation
A stolen subway day-pass that lasts a year is a gift to anyone who snags it. Long Kerberos lifetimes stretch how long a grabbed ticket stays useful. Tighten the clock; do not treat "less auth chatter" as free security.
Full Explanation
Ticket maximum lifetimes and renewals bound how long a stolen TGT or service ticket remains usable. Excessively long policies expand the reuse window after credential or ticket theft. Lifetime settings do not replace password hygiene, nor does Kerberos ignore them after a single daily login. Reduced authentication volume is not a justification for unbounded ticket validity.