- Home
- All questions
- Question 267
CompTIA Security+ study material · question 267 of 611
An attacker repeatedly requests a new out-of-band code hoping to reset the failed-attempt counter. What does NIST require?
Show the answer
Answer: D. Generating a new secret must not reset the failed authentication count
Otherwise rate limiting could be escaped simply by asking for a fresh code between guesses.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.3.2