Study. uk . com
  1. Home
  2. All questions
  3. Question 267

CompTIA Security+ study material · question 267 of 611

An attacker repeatedly requests a new out-of-band code hoping to reset the failed-attempt counter. What does NIST require?

  1. The account must be locked after the first new code
  2. The counter must be reset with each new code
  3. Codes must be reissued only by an administrator
  4. Generating a new secret must not reset the failed authentication count
Show the answer

Answer: D. Generating a new secret must not reset the failed authentication count

Otherwise rate limiting could be escaped simply by asking for a fresh code between guesses.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.3.2

Challenge yourself on this topic → Study as cards