SY0-701 · Question #674
A security analyst needs to improve the company's authentication policy following a password audit. Which of the following should be included in the policy? (Choose two.)
The correct answer is A. Length D. Something you have. Emphasizing password length over complexity is a best practice. The National Institute of Standards and Technology (NIST) recommends a minimum password length of 8 characters, with a preference for longer passphrases, such as 12 characters or more, to increase security and…
Question
A security analyst needs to improve the company's authentication policy following a password audit. Which of the following should be included in the policy? (Choose two.)
Options
- ALength
- BComplexity
- CLeast privilege
- DSomething you have
- ESecurity keys
- FBiometrics
How the community answered
(51 responses)- A80% (41)
- B6% (3)
- C2% (1)
- E2% (1)
- F10% (5)
Explanation
Emphasizing password length over complexity is a best practice. The National Institute of Standards and Technology (NIST) recommends a minimum password length of 8 characters, with a preference for longer passphrases, such as 12 characters or more, to increase security and Implementing multi-factor authentication (MFA) by requiring a physical item, like a security key or smartphone, adds a robust layer of security. This "something you have" factor ensures that even if a password is compromised, unauthorized access is still prevented. Incorporating these elements aligns with current security best practices and strengthens your organization's defense against unauthorized access.
Community Discussion
No community discussion yet for this question.