- Home
- All questions
- Question 486
CISSP study material · question 486 of 500
Which three practices does OWASP's 2025 authentication entry recommend? Choose three.
Show the answer
Answer: D. Never ship or deploy with default credentials, especially for administrative users.
B. Check new or changed passwords against a list of the worst passwords.
C. Validate credentials at account creation and password change against lists of known breached credentials.
OWASP recommends weak password checks against a worst-passwords list, validation against known breached credentials at creation and change, and never shipping with default credentials.
Source: OWASP Top 10 A07:2025 (OWASP) — OWASP Top 10:2025 A07 Authentication Failures > How to prevent