How would you perform a secure password reset when a user forgot their password?

Prepare for your Desktop Support Technician Interview with our test that features flashcards and multiple choice questions, each with hints and explanations. Ace your interview with confidence!

Multiple Choice

How would you perform a secure password reset when a user forgot their password?

Explanation:
The main idea is to verify the user’s identity before making any password changes and to enforce safeguards after the reset. Confirming identity through MFA or security questions ensures the person requesting the reset is who they say they are, rather than someone acting with stolen or guessed credentials. Once verified, unlocking the account and resetting the password in the directory service (AD or the identity provider) guarantees that the reset follows the organization’s policy controls and auditing. Requiring a password change on the next login prevents reuse of an old password and helps ensure the user adopts a new credential, while forcing MFA on first sign-in adds ongoing protection against credential theft or misuse after the reset. In contrast, changing without verification risks unauthorized access, disabling the account and never resetting leaves the user unable to access resources, and sending the password via email is insecure and not compliant with security best practices.

The main idea is to verify the user’s identity before making any password changes and to enforce safeguards after the reset. Confirming identity through MFA or security questions ensures the person requesting the reset is who they say they are, rather than someone acting with stolen or guessed credentials. Once verified, unlocking the account and resetting the password in the directory service (AD or the identity provider) guarantees that the reset follows the organization’s policy controls and auditing. Requiring a password change on the next login prevents reuse of an old password and helps ensure the user adopts a new credential, while forcing MFA on first sign-in adds ongoing protection against credential theft or misuse after the reset. In contrast, changing without verification risks unauthorized access, disabling the account and never resetting leaves the user unable to access resources, and sending the password via email is insecure and not compliant with security best practices.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy