What should you do with the initial credentials assigned to a user or after a reset?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

What should you do with the initial credentials assigned to a user or after a reset?

Explanation:
Providing a unique temporary password to each user and requiring a password change immediately after first use is the strongest way to protect accounts during onboarding or after a reset. This approach ensures the initial credential is known only to the intended user and prevents attackers from exploiting a shared or predictable starting password. If you use a common initial password for all users, or keep using the same value after the first login, a single compromised credential could unlock many accounts. Merely scheduling a change at the next login without guaranteeing uniqueness still leaves room for exposure if the initial value was shared or guessed. Requiring a unique initial password for each user and forcing an immediate change at first use closes that gap and aligns with secure credential practices.

Providing a unique temporary password to each user and requiring a password change immediately after first use is the strongest way to protect accounts during onboarding or after a reset. This approach ensures the initial credential is known only to the intended user and prevents attackers from exploiting a shared or predictable starting password. If you use a common initial password for all users, or keep using the same value after the first login, a single compromised credential could unlock many accounts. Merely scheduling a change at the next login without guaranteeing uniqueness still leaves room for exposure if the initial value was shared or guessed. Requiring a unique initial password for each user and forcing an immediate change at first use closes that gap and aligns with secure credential practices.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy