A security analyst needs to improve the company’s authentication policy following a password audit. Which of the following should be included in the policy? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Length.
Why this is the answer
The question asks for elements to include in an authentication policy to improve it after a password audit. Length is a fundamental characteristic of a strong password and directly impacts its resistance to brute-force attacks, making it a crucial policy element. Complexity, while often paired with length, is less effective on its own than a long, random password. "Something you have" and "security keys" are types of authentication factors (multi-factor authentication), not policy elements for password improvement. Biometrics is another authentication factor, not a password policy element. Least privilege is an access control principle, not directly related to password policy specifics.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed