- Home
- All questions
- Question 260
CompTIA Security+ study material · question 260 of 611
Under current NIST guidance, when must a verifier force a password change?
Show the answer
Answer: D. Only when there is evidence the authenticator has been compromised
Scheduled expiry is discouraged; a forced change is warranted by evidence of compromise, not by the calendar.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.1 Passwords