During a baseline review, you discover an engineering workstation still uses the vendor's default administrator account and password documented in the public manual. Which immediate corrective action carries the highest security value?
- A.Add an antivirus exclusion for the vendor application directory
- B.Increase the screen-saver lock timeout to reduce login frequency
- C.Enable the workstation's guest account for read-only access
- D.Change the default credentials and create individually attributable accounts for engineers
Why D is correct
Default credentials published in vendor documentation are among the first things attackers try. Replacing them and moving to per-user accounts both closes a well-known entry point and restores accountability for actions taken on the workstation.
Know someone studying for OT Security Fundamentals? Send them this one.