CompTIA Security+ SY0-701 Practice Question
A company's leadership has mandated the implementation of stronger controls around password management to improve security posture. As part of this initiative, the CISO is revising the company's password policy. Which of the following changes to the password policy BEST aligns with effective security governance practices?
Disabling the account lockout feature after several incorrect password attempts.
Increasing the mandatory password change frequency to every 30 days.
Implementing a passphrase policy with a mix of upper and lower case letters, numbers, and symbols.
Mandating biometric authentication in addition to the password for all user accounts.