nerdexam
CompTIA

SY0-301 · Question #669

Which of the following should be done before resetting a user's password due to expiration?

The correct answer is B. Verify the user's identity. Before resetting any password, the administrator must verify the identity of the person making the request. This is a critical social engineering defense - an attacker could impersonate an employee and request a password reset to gain unauthorized access. Verifying domain…

Security operations

Question

Which of the following should be done before resetting a user's password due to expiration?

Options

  • AVerify the user's domain membership.
  • BVerify the user's identity.
  • CAdvise the user of new policies.
  • DVerify the proper group membership.

How the community answered

(53 responses)
  • A
    2% (1)
  • B
    92% (49)
  • C
    4% (2)
  • D
    2% (1)

Explanation

Before resetting any password, the administrator must verify the identity of the person making the request. This is a critical social engineering defense - an attacker could impersonate an employee and request a password reset to gain unauthorized access. Verifying domain membership or group membership confirms account attributes, but neither confirms that the person requesting the reset is actually the legitimate account owner. Advising on new policies is useful but irrelevant to the security of the reset process itself. Identity verification is the foundational step that prevents account takeover.

Topics

#identity verification#password management#authentication

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice