A library stores backup Domain Admin credentials in a ticketing system readable by many staff. How should identity risk be framed?
Select an answer to reveal the explanation.
Short Explanation
The strongest Domain Admin password still fails if it is taped to the break-room fridge — or a ticket queue everyone can open. Secret sprawl outside AD bypasses directory ACLs. Keep privileged creds in a real vault with tight ACL eyes.
Full Explanation
Identity security includes where privileged secrets are stored, not only AD object ACLs. Credentials in broadly readable ITSM or wiki systems allow low-privilege staff or attackers with helpdesk access to obtain Domain Admin material. Subject-line "confidential" labels and email distribution worsen sprawl. Report out-of-directory privileged secret exposure as part of AD-related hygiene.