Passwords for default accounts and default administrative accounts should be?
A.
Changed within 30 days after installing a system on the network.
B.
Reset to the default password before installing a system on the network.
C.
Changed before installing a system on the network.
D.
Configured to expire in 30 days.
The Answer Is:
C
This question includes an explanation.
Explanation:
According toRequirement 2.2.6,default passwords must be changed before systems are installed on the network. The use of default credentials (such as "admin/admin") presents a major security risk and is a well-known vector for breaches.
Option A:❌Incorrect. Changing within 30 days is not soon enough per PCI DSS.
Option B:❌Incorrect. Resetting to default would defeat the purpose of secure configuration.
Option C:✅Correct. The requirement is to change default passwordsprior to network connection.
Option D:❌Incorrect. Password expiration policies are a separate topic under Requirement 8.