nerdexam
CompTIA

220-1102 · Question #186

A systems administrator needs to reset a users password because the user forgot it. The systems administrator creates the new password and wants to further protect the user's account. Which of the fol

The correct answer is A. Require the user to change the password at the next log-in.. Requiring the user to change the password at next login is a security best practice when an admin resets a password. Since the administrator knows the temporary password, forcing an immediate user-defined change ensures only the account owner knows the final credential. Preventin

Security

Question

A systems administrator needs to reset a users password because the user forgot it. The systems administrator creates the new password and wants to further protect the user's account. Which of the following should the systems administrator do?

Options

  • ARequire the user to change the password at the next log-in.
  • BDisallow tie user from changing the password.
  • CDisable the account
  • DChoose a password that never expires.

How the community answered

(50 responses)
  • A
    80% (40)
  • B
    6% (3)
  • C
    12% (6)
  • D
    2% (1)

Explanation

Requiring the user to change the password at next login is a security best practice when an admin resets a password. Since the administrator knows the temporary password, forcing an immediate user-defined change ensures only the account owner knows the final credential. Preventing the user from changing the password (B) is a security risk and bad practice. Disabling the account (C) defeats the purpose of a reset. A never-expiring password (D) reduces security posture. Option A limits the window during which the admin-set password is valid and enforces user ownership of their credentials.

Topics

#Password reset#Account security#Security best practices#User management

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice