What must be done with development, test, and custom application accounts before activation?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

What must be done with development, test, and custom application accounts before activation?

Explanation:
Before production activation, all development, test, and custom application accounts (and their user IDs and passwords) must be removed or disabled. This minimizes the risk of backdoors or weak credentials entering the live environment and ensures that access in production is limited to production-approved accounts with properly controlled privileges. Keeping these accounts or their credentials active—even if renamed—can introduce opportunities for unauthorized access and complicate auditing and change management. If testing is still needed, use separate, controlled test environments and disable or remove those accounts before going live. This practice aligns with reducing attack surfaces and enforcing proper account lifecycle management.

Before production activation, all development, test, and custom application accounts (and their user IDs and passwords) must be removed or disabled. This minimizes the risk of backdoors or weak credentials entering the live environment and ensures that access in production is limited to production-approved accounts with properly controlled privileges. Keeping these accounts or their credentials active—even if renamed—can introduce opportunities for unauthorized access and complicate auditing and change management. If testing is still needed, use separate, controlled test environments and disable or remove those accounts before going live. This practice aligns with reducing attack surfaces and enforcing proper account lifecycle management.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy