Which statement best describes the required validation before installing a system on the network regarding vendor defaults and default accounts?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Which statement best describes the required validation before installing a system on the network regarding vendor defaults and default accounts?

Explanation:
Before placing a system on the network, you must establish a secure starting point by hardening vendor defaults and pruning accounts. Vendor-supplied defaults are widely known and often used as an easy entry point for attackers. If these defaults remain, or if default accounts that aren’t needed stay enabled, the system has predictable access paths that can be exploited. The best practice is to change all vendor defaults and remove or disable any unnecessary default accounts before installation. This minimizes the attack surface from day one and ensures a solid security baseline for ongoing configuration.

Before placing a system on the network, you must establish a secure starting point by hardening vendor defaults and pruning accounts. Vendor-supplied defaults are widely known and often used as an easy entry point for attackers. If these defaults remain, or if default accounts that aren’t needed stay enabled, the system has predictable access paths that can be exploited. The best practice is to change all vendor defaults and remove or disable any unnecessary default accounts before installation. This minimizes the attack surface from day one and ensures a solid security baseline for ongoing configuration.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy