セキュリティアナリストは、パスワード監査を受けて、会社の認証ポリシーを改善する必要があります。ポリシーに含めるべき項目は次のうちどれですか?(2つ選択してください。)
正解:A,D
Emphasizing password length over complexity is a best practice. The National Institute of Standards and Technology (NIST) recommends a minimum password length of 8 characters, with a preference for longer passphrases, such as 12 characters or more, to increase security and memorability.
Implementing multi-factor authentication (MFA) by requiring a physical item, like a security key or smartphone, adds a robust layer of security. This "something you have" factor ensures that even if a password is compromised, unauthorized access is still prevented.
Incorporating these elements aligns with current security best practices and strengthens your organization's defense against unauthorized access.