IEC 62443-2-4 expects service providers to define how they handle account management for the systems they support. A clear failure of this capability would be:
A.Leaving vendor default administrative accounts active after commissioning
B.Removing default accounts and enforcing unique credentials
C.Disabling unused accounts promptly
D.Documenting every account and its purpose
Why A is correct
Leaving default administrative accounts active is a well-known, easily exploited weakness and a clear failure of the account-management capability. The other options describe sound practices the standard encourages. Eliminating defaults and enforcing unique, least-privilege credentials is fundamental in OT.
Know someone studying for ISA/IEC 62443? Send them this one.
CyberCertPrep gives you 20 free ISA/IEC 62443 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISA/IEC 62443 and ISA/IEC are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISA/IEC or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
A CSMS classifies a risk as high likelihood and high consequence. The classification's main purpose in the next CSMS step is to: