Study. uk . com
  1. Home
  2. All questions
  3. Question 312

CISSP study material · question 312 of 500

A team proposes meeting a phishing-resistance requirement by mandating 20-character passwords. What does NIST SP 800-63B say?

  1. Passwords are phishing-resistant when combined with a blocklist check.
  2. Passwords become phishing-resistant above 16 characters.
  3. Passwords are not phishing-resistant, whatever their length or composition.
  4. Passwords are phishing-resistant only when entered through a password manager.
Show the answer

Answer: C. Passwords are not phishing-resistant, whatever their length or composition.

SP 800-63B states plainly that passwords are not phishing-resistant; length and composition do not change that property.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 3.1.1 Passwords

Challenge yourself on this topic → Study as cards