While using "Forgot Password" feature by user to recover the password, what should be checked first
whether the credentials provided are valid and correct
whether account is already disabled
whether account is locked
whether the CAPTCHA values entered by the user same as what is in the image