- Home
- All questions
- Question 317
CompTIA Security+ study material · question 317 of 611
A one-time password is truncated to six digits. What obligation does that place on the verifier?
Show the answer
Answer: A. It must rate-limit failed authentication attempts
Six digits is well under 64 bits, so throttling is what keeps online guessing impractical.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.4