What should you do with vendor-supplied defaults before installing a system on the network?

Prepare for the PCI ASV Online Test with multiple choice questions, hints, and detailed explanations. Enhance your knowledge and get ready for your exam efficiently!

Multiple Choice

What should you do with vendor-supplied defaults before installing a system on the network?

Explanation:
Vendor defaults are widely known and provide easy access points for attackers. Before putting a system on the network, you should personalize credentials and settings so no default password, account, or configuration remains active. Changing all vendor-supplied defaults and removing or disabling unnecessary default accounts reduces the attack surface and prevents unauthorized access. For example, set a strong, unique administrator password, replace default SNMP community strings, and disable or remove any default accounts that aren’t needed. Merely changing one or two defaults leaves other backdoors open, so the best practice is to change all defaults and disable unused accounts.

Vendor defaults are widely known and provide easy access points for attackers. Before putting a system on the network, you should personalize credentials and settings so no default password, account, or configuration remains active. Changing all vendor-supplied defaults and removing or disabling unnecessary default accounts reduces the attack surface and prevents unauthorized access. For example, set a strong, unique administrator password, replace default SNMP community strings, and disable or remove any default accounts that aren’t needed. Merely changing one or two defaults leaves other backdoors open, so the best practice is to change all defaults and disable unused accounts.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy