QS0029-03: Password Control Policy Flashcards

1
Q

QS0029-02: Password Control Policy

Describe the meaning of “User-level account.”

A

Accounts created for use by individuals that will be accessing assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

QS0029-02: Password Control Policy

How is the “Service Account” defined?

A

An account that provides a security context for services, esp automated services. e.g., an account that runs a windows task, service, or cronjob, or is used to auto-pull from git or docker.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

QS0029-02: Password Control Policy

How often should passwords for sensitive systems be changed?

A

Passwords must be changed at least every three months.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

QS0029-02: Password Control Policy

What is NOT a best practice for password policy (summarize)?

A

Revealing or provide hints about your password to anyone, at any time, ever.

Using the “Remember Password” feature of applications (e.g., Chrome, Bing, Outlook).

Storing passwords outside of the password vault - this includes paper.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

QS0029-02: Password Control Policy

What should passwords not contain?

A

Personal information, names of family, and birthdate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

QS0029-02: Password Control Policy

What action you must consider if an account or password compromise is suspected?

A

Report the incident to DevOps and change all passwords.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

QS0029-02: Password Control Policy

Where should be passwords stored?

A

In the company password vault.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly