Why must vendor-supplied default passwords be changed before deploying a system in the CDE?
- A.Default passwords are publicly known and easily exploited by attackers
- B.Default passwords are too long to remember, which needs review only when the contract is first signed, not during the relationship
- C.Changing passwords is required for warranty compliance, which applies only to Level 1 merchants and to no other validation tier
- D.Default passwords expire after 30 days
Why A is correct
Vendor-supplied default passwords are publicly documented and well-known to attackers. Leaving them unchanged provides trivial unauthorized access to systems in the cardholder data environment.
Know someone studying for PCI DSS? Send them this one.