David is the system administrator for a company. A user calls him and tells that he has forgotten his password and requests a new password. What should David do?
  1. David should change the password only after verifying the user's identity against the records.
  2. David should reset the password.
  3. David should ask him to send the request over postal mail.
  4. David should not change the password.
Explanation
Answer- A - The password should be changed only after verifying that the person is who he/she claims to be.

Key Takeaway: Changing any authentication details without proper verification procedure may lead to data theft. Most social engineering scenarios are carried out this way, therefore, the credentials need to be changed only after a positive verification.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz