- Home
- All questions
- Question 258
CompTIA Security+ study material · question 258 of 611
Under the current NIST digital identity guidelines, what is the minimum length for a password used as the only authentication factor?
Show the answer
Answer: B. 15 characters
Single-factor passwords must be at least fifteen characters. Eight is the floor only where the password is part of a multi-factor flow.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.1 Passwords