The correct answer is:
A. assigned by the security administrator for first time logon.
Explanation:
Initial password assignment should be done discretely by the security
administrator. Passwords should be changed often (e.g., every 30
days); however, changing should not be voluntary, it should be
required by the system. Systems should not permit previous passwords
to be used again; old passwords may have been compromised and would
thus permit unauthorized access. Passwords should not be displayed in
any form.
答案A應該是正確的, 首次密碼由安全管理員指派,
使用者登入後要馬上修改密碼
BCD都不對