Henry wants to prevent password reuse outside of his organization from impacting the accounts his staff use. Which of the following password settings can have the largest impact if passwords are reused outside of his organization and they are breached due to a security issue at the third-party site or service?
Answer Options
Password expiration policies
Password length policies
Password complexity policies
Password minimum age policies
Correct Answer: A
Explanation
Password expiration polices help reduce the length of time a password could be exposed for. Henry knows that if his staff change their password periodically that it can help avoid issues with reuse on other sites. He also knows that multifactor is a more effective solution and that he should focus his time there as well. Password length and complexity don’t matter if the password was compromised elsewhere, and minimum age policies are used to prevent reuse in the organization by resetting passwords over and over again to return to an original desired password. Note that policies like this don’t stop reuse outside of a user’s organization on 3 rd party sites!