CompTIA Server+ SK0-005 Practice Question
During a routine health check you discover that users can no longer authenticate to a Windows Server 2019 web application that relies on Kerberos. The System log on the server shows the following entry:
Event ID 4, Source Kerberos
"The Kerberos client received a KRB_AP_ERR_SKEW error. The time on the client and server machines might be out of sync."
Network connectivity and DNS resolution to the domain controllers are normal.
Which action will MOST quickly restore user access while following best practices?
Disjoin the computer from the domain, then rejoin it to rebuild the secure channel.
Purge the local Kerberos ticket cache with the klist utility and reboot the server.
Increase the "Maximum tolerance for computer clock synchronization" Kerberos policy from 5 to 30 minutes.
Resynchronize the server clock with a reliable NTP source and restart or resync the Windows Time (w32time) service.