Which statement accurately reflects the handling of generic user IDs and shared IDs in system administration?

Study for the PCI Data Security Standard Test. Utilize flashcards and multiple-choice questions, each offering hints and detailed explanations. Prepare thoroughly for your exam and ensure compliance with PCI DSS!

Multiple Choice

Which statement accurately reflects the handling of generic user IDs and shared IDs in system administration?

Explanation:
The key idea here is accountability through unique, traceable access. When generic user IDs or shared accounts are used for system administration, actions cannot be reliably linked to a single person. This undermines auditing, makes it easy for credentials to be misused, and increases risk if someone’s access is shared or reused by others. The proper approach is to disable or remove generic IDs so each administrator uses their own unique user ID with appropriate, least-privilege access. If elevated or automated tasks must run without a person present, use separate, tightly controlled service or administrator accounts that are managed and audited, rather than sharing a single generic account. The other options imply keeping or relying on shared or generic access or overemphasize group IDs, which does not support the necessary traceability and control.

The key idea here is accountability through unique, traceable access. When generic user IDs or shared accounts are used for system administration, actions cannot be reliably linked to a single person. This undermines auditing, makes it easy for credentials to be misused, and increases risk if someone’s access is shared or reused by others. The proper approach is to disable or remove generic IDs so each administrator uses their own unique user ID with appropriate, least-privilege access. If elevated or automated tasks must run without a person present, use separate, tightly controlled service or administrator accounts that are managed and audited, rather than sharing a single generic account. The other options imply keeping or relying on shared or generic access or overemphasize group IDs, which does not support the necessary traceability and control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy