CompTIA Security+ SY0-701 Practice Question
An administrator is tasked with enhancing the password policy to protect against unauthorized attempts to guess user credentials. Which of the following would be the BEST method to mitigate the risk of these types of attacks?
Increase the minimum password length requirement to 16 characters
Set up alerts to monitor accounts for a high number of failed login attempts
Require users to change their password every 30 days
Implement an account lockout policy after three unsuccessful login attempts