Free practice · ordering · hard

Practice

Order the complete account-protection path

Arrange the chapter's complete account-security workflow.

Account protection lifecycle

Secure access continues after a password is created

  1. OwnerUse an individual approved account
  2. AccessGrant only the current work need
  3. CredentialStore a unique secret safely
  4. MFAApprove only an expected sign-in
  5. RecoveryProtect recovery routes and sessions
  6. ReviewAct on changes, alerts, and departures

Identity, least privilege, unique credentials, MFA, protected recovery, and alert review work as one account-control system.

Arrange in the correct order
  1. 1. Revoke, reset, and report unexpected changes promptly
  2. 2. Review alerts, sessions, devices, and access regularly
  3. 3. Protect recovery methods, codes, and contacts
  4. 4. Enroll an approved MFA method and verify every prompt
  5. 5. Create a unique credential in the approved password manager
  6. 6. Confirm the account owner, purpose, and required access