Study. uk . com
  1. Home
  2. All questions
  3. Question 486

CISSP study material · question 486 of 500

Which three practices does OWASP's 2025 authentication entry recommend? Choose three.

  1. Require passwords to be changed on a fixed schedule regardless of evidence.
  2. Check new or changed passwords against a list of the worst passwords.
  3. Validate credentials at account creation and password change against lists of known breached credentials.
  4. Never ship or deploy with default credentials, especially for administrative users.
Show the answer

Answer: D. Never ship or deploy with default credentials, especially for administrative users.
B. Check new or changed passwords against a list of the worst passwords.
C. Validate credentials at account creation and password change against lists of known breached credentials.

OWASP recommends weak password checks against a worst-passwords list, validation against known breached credentials at creation and change, and never shipping with default credentials.

Source: OWASP Top 10 A07:2025 (OWASP) — OWASP Top 10:2025 A07 Authentication Failures > How to prevent

Challenge yourself on this topic → Study as cards