What Is a Dormant Account?
A dormant account is an enabled account that has not been used for an extended period but still retains the ability to authenticate or access resources. Certification questions may present an old employee, vendor, administrator, test, or service account and ask why it creates risk. Because dormant accounts are rarely monitored by their original owners, attackers may use them without immediately attracting attention. They may also retain outdated passwords, excessive permissions, or access to systems that are no longer reviewed. Organizations should define inactivity thresholds, identify unused accounts automatically, confirm whether they remain necessary, and disable or remove them according to policy. Service accounts require additional investigation because inactivity in interactive logins does not always mean the account is unused by an application or scheduled process. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!
