- Home
- All questions
- Question 312
CISSP study material · question 312 of 500
A team proposes meeting a phishing-resistance requirement by mandating 20-character passwords. What does NIST SP 800-63B say?
Show the answer
Answer: C. Passwords are not phishing-resistant, whatever their length or composition.
SP 800-63B states plainly that passwords are not phishing-resistant; length and composition do not change that property.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 3.1.1 Passwords