Study. uk . com
  1. Home
  2. All questions
  3. Question 260

CompTIA Security+ study material · question 260 of 611

Under current NIST guidance, when must a verifier force a password change?

  1. Annually, at the access review
  2. Whenever the user logs in from a new device
  3. Every ninety days
  4. Only when there is evidence the authenticator has been compromised
Show the answer

Answer: D. Only when there is evidence the authenticator has been compromised

Scheduled expiry is discouraged; a forced change is warranted by evidence of compromise, not by the calendar.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.1 Passwords

Challenge yourself on this topic → Study as cards