CompTIA Security+ SY0-701 Practice Question
As an IT manager, you have been tasked with reviewing the company's password policies to ensure they align with best practices for security. Upon examination, you find out that the policy requires all employees to change their passwords every 90 days. What change would you recommend to improve password security effectively while balancing user convenience?
Remove the password expiration policy and allow users to keep passwords indefinitely.
Mandate that all users create passwords with a minimum length of 30 characters.
Implement multi-factor authentication and increase password complexity requirements.
Shorten the password expiration period to require changes every 45 days.