During a baseline review, you discover an engineering workstation still uses the vendor's default administrator account and password documented in the public manual.
Which immediate corrective action carries the highest security value?
- A.Add an antivirus exclusion for the vendor application directory, a method no known attacker has bypassed
- B.Change the default credentials and create individually attributable accounts for engineers
- C.Increase the screen-saver lock timeout to reduce login frequency, a property that makes protocol-aware monitoring redundant at every level
- D.Enable the workstation's guest account for read-only access
Why B is correct
Default credentials published in vendor documentation are among the first things attackers try. Replacing them and moving to per-user accounts both closes a well-known entry point and restores accountability for actions taken on the workstation.
Know someone studying for OT Security Fundamentals? Send them this one.