Study. uk . com
  1. Home
  2. All questions
  3. Question 46

CISSP study material · question 46 of 500

A security manager is rewriting the password policy for a workforce portal to align with NIST SP 800-63B-4. The current policy mandates a mix of upper case, digits and symbols, expires every password after 90 days, and screens new passwords against a blocklist of breached values. Which two changes bring the policy into line? Choose two.

  1. Add a knowledge-based security question that the user must answer at every password change.
  2. Drop the composition rules that mandate particular character types within the password.
  3. Drop the fixed 90-day expiry and force a change only on evidence that the password is compromised.
  4. Drop the blocklist screening and rely on the composition rules to keep weak passwords out.
Show the answer

Answer: B. Drop the composition rules that mandate particular character types within the password.
C. Drop the fixed 90-day expiry and force a change only on evidence that the password is compromised.

Character-mixing rules and scheduled expiry are both barred; a forced change needs evidence of compromise. Blocklist screening is required, and knowledge-based questions are unacceptable secrets.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > Password Requirements

Challenge yourself on this topic → Study as cards