cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
ivanborgiey
Newcomer I

SSCP practice exam question.

I have a question regarding this matter. SSCP.JPG

 

Why is the answer is No expiration? I checked the NIST 800-63b but I didn't find anything about it

15 Replies
DarkCerberus
Viewer

It's stated that we are no longer supposed to enforce password changes. In other words, we cannot "force" a user to change their password. 

dcontesti
Community Champion

I admit that I have not read the entire thread BUT the question is wrong.

 

According to NIST 800-63B

 

  • No forced password changes:
    Avoid forcing users to change their passwords frequently, as it often leads to users creating weaker passwords. 

The header of that section is misleading.  You MUST read the entire document.

 

REALLY terrible question..  Should be corrected for removed from the Materials<  Where did this question come from?  Is this from an ISC2 publication?  

 

Regards

 

d

 

xuiopika
Viewer


Passing SSCP felt easy after preparing with Passexam-hub. Their questions were so close to the real exam. Highly impressed!

akkem
Contributor III

Agree! NIST guidance, no longer enforce periodic password roatation. Instead requires complex passwords combing with MFA.
https://pages.nist.gov/800-63-3/sp800-63b.html
akkem
Contributor III

@xuiopika - Congratulations passing on SSCP!
Jaysamfong
Viewer

This is what I found: NIST SP 800-63b

Section 5.1.1.2 - Memorized Secret Verifiers states:

   "Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).  However, verifiers SHALL force a change if there is evidence of compromise of the authenticator."

 

Hope this helps! Technologies, tools, and processes do evolve based on evolving threats and evolving of these things mentioned.