nerdexam
CyberArk

ACCESS-DEF · Question #21

Which options are available with Self-Service Password Reset? (Choose three.)

The correct answer is A. Enable users with Active Directory accounts who have forgotten their password to log in and reset it. Note: The question asks for three correct answers, but only A is listed here. Based on standard Self-Service Password Reset (SSPR) capabilities, the three correct answers are likely A, E, and F. Option A is correct because SSPR's core purpose is exactly this - allowing users…

Authentication and Authorization

Question

Which options are available with Self-Service Password Reset? (Choose three.)

Options

  • AEnable users with Active Directory accounts who have forgotten their password to log in and reset it.
  • BPerform Self-Service Password Reset for the Organization's corporate accounts, such as Twitter, Facebook, or Instagram.
  • CUsers must log in after a password reset.
  • DA maximum number of times can be specified that users can reset their password within a specific timeframe.
  • EUser must respond to a CAPTCHA before resetting their password.
  • FUse Helpdesk Caller Identity (Identity Verification) to confirm user identity.

How the community answered

(25 responses)
  • A
    88% (22)
  • C
    8% (2)
  • E
    4% (1)

Explanation

Note: The question asks for three correct answers, but only A is listed here. Based on standard Self-Service Password Reset (SSPR) capabilities, the three correct answers are likely A, E, and F.

Option A is correct because SSPR's core purpose is exactly this - allowing users with Active Directory accounts to self-serve a forgotten password reset without IT intervention.

Option E is correct because SSPR implementations commonly require CAPTCHA completion as a bot-prevention security layer before proceeding with the reset flow.

Option F is correct because Helpdesk Caller Identity (Identity Verification) is a built-in mechanism allowing help desk agents to verify a caller's identity before initiating a reset on their behalf.

Why the distractors are wrong:

  • B is wrong - SSPR operates on organizational directory accounts (AD/LDAP), not third-party social media accounts.
  • C is wrong - SSPR typically authenticates the user automatically upon successful reset; requiring a separate login step would defeat the convenience purpose.
  • D is wrong - SSPR does not expose a configurable rate-limit for how many times a user can reset their password within a timeframe; that level of lockout control lives in account lockout policy, not SSPR settings.

Memory tip: Think of SSPR as the "front door" for locked-out AD users - it lets them in (A), checks they're human via CAPTCHA (E), and lets the help desk vouch for them (F). Everything else (social media, login steps, reset quotas) is outside SSPR's scope.

Topics

#Self-Service Password Reset#Authentication#Identity Verification#Password Management

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice