SY0-301 · Question #669
Which of the following should be done before resetting a user's password due to expiration?
The correct answer is B. Verify the user's identity. Before resetting any password, the administrator must verify the identity of the person making the request. This is a critical social engineering defense - an attacker could impersonate an employee and request a password reset to gain unauthorized access. Verifying domain…
Question
Which of the following should be done before resetting a user's password due to expiration?
Options
- AVerify the user's domain membership.
- BVerify the user's identity.
- CAdvise the user of new policies.
- DVerify the proper group membership.
How the community answered
(53 responses)- A2% (1)
- B92% (49)
- C4% (2)
- D2% (1)
Explanation
Before resetting any password, the administrator must verify the identity of the person making the request. This is a critical social engineering defense - an attacker could impersonate an employee and request a password reset to gain unauthorized access. Verifying domain membership or group membership confirms account attributes, but neither confirms that the person requesting the reset is actually the legitimate account owner. Advising on new policies is useful but irrelevant to the security of the reset process itself. Identity verification is the foundational step that prevents account takeover.
Topics
Community Discussion
No community discussion yet for this question.