Study. uk . com
  1. Home
  2. All questions
  3. Question 303

CompTIA Security+ study material · question 303 of 611

A service account cannot use an interactive multi-factor prompt. What should it rely on instead?

  1. A longer password with no expiry
  2. Managed keys or certificates issued and rotated by a secrets platform
  3. A shared password held by the operations team
  4. An exemption from the account lifecycle
Show the answer

Answer: B. Managed keys or certificates issued and rotated by a secrets platform

Machine accounts need the same lifecycle discipline as human ones, delivered through automation rather than prompts.

Source: OWASP Secrets Management Cheat Sheet (OWASP) — OWASP Secrets Management Cheat Sheet › Identity and Access Management

Challenge yourself on this topic → Study as cards