(a) Why is it a problem to use the same password at multiple sites?
(b) Why is it difficult to enforce a policy of using a different password at each site?
(c) Why are password duration policies important?
(d) What are password resets?
(e) Why are password resets dangerous?
(f) How can password resets be automated?
(g) Why are password reset questions difficult to create?
(h) How may password resets be handled in high-risk environments?

