Which statement accurately reflects the handling of generic user IDs and shared IDs in system administration?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

Which statement accurately reflects the handling of generic user IDs and shared IDs in system administration?

Explanation:
The key idea here is accountability through unique, traceable access. When generic user IDs or shared accounts are used for system administration, actions cannot be reliably linked to a single person. This undermines auditing, makes it easy for credentials to be misused, and increases risk if someone’s access is shared or reused by others. The proper approach is to disable or remove generic IDs so each administrator uses their own unique user ID with appropriate, least-privilege access. If elevated or automated tasks must run without a person present, use separate, tightly controlled service or administrator accounts that are managed and audited, rather than sharing a single generic account. The other options imply keeping or relying on shared or generic access or overemphasize group IDs, which does not support the necessary traceability and control.

The key idea here is accountability through unique, traceable access. When generic user IDs or shared accounts are used for system administration, actions cannot be reliably linked to a single person. This undermines auditing, makes it easy for credentials to be misused, and increases risk if someone’s access is shared or reused by others. The proper approach is to disable or remove generic IDs so each administrator uses their own unique user ID with appropriate, least-privilege access. If elevated or automated tasks must run without a person present, use separate, tightly controlled service or administrator accounts that are managed and audited, rather than sharing a single generic account. The other options imply keeping or relying on shared or generic access or overemphasize group IDs, which does not support the necessary traceability and control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy