Multiple choice technology security

What is suggested as the leading practice for the maximum length of time before users are forced to change their passwords?

  1. 60 days

  2. 180 days

  3. 120 days

  4. 90 days

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

90 days is widely recommended as the maximum password age to balance security with usability. More frequent changes (60 days) can lead to users writing down passwords or choosing weak ones. Longer intervals (120-180 days) increase exposure if passwords are compromised. The 90-day standard comes from NIST and other security frameworks as a practical compromise.

AI explanation

To answer this question, you need to understand the leading practice for password expiration and the maximum recommended length of time before users are forced to change their passwords.

Option A) 60 days - This option is incorrect. A password expiration period of 60 days is shorter than the recommended maximum length of time.

Option B) 180 days - This option is incorrect. A password expiration period of 180 days is longer than the recommended maximum length of time.

Option C) 120 days - This option is incorrect. A password expiration period of 120 days is longer than the recommended maximum length of time.

Option D) 90 days - This option is correct. The leading practice for the maximum length of time before users are forced to change their passwords is typically 90 days. This helps maintain security by ensuring that passwords are regularly updated and reduces the risk of unauthorized access due to compromised passwords.

The correct answer is D. This option is correct because it aligns with the leading practice of a 90-day password expiration period.