A city helpdesk group can reset passwords on privileged user accounts. What risk should be highlighted?
Select an answer to reveal the explanation.
Short Explanation
Whoever can reset the vault combination effectively owns the vault. Helpdesk rights over Domain Admin-class users turn a social or helpdesk foothold into privilege. Ticket numbers do not shrink that blast radius.
Full Explanation
Delegated password reset on privileged accounts allows an attacker who controls the helpdesk principal to take over those identities. That is a classic over-privilege control gap. Directory can and does grant such rights beyond Domain Admins through ACLs and roles. The issue applies strongly to interactive privileged users, not only service accounts.