Question: An analyst is evaluating the security of a web application that does not hold sensitive or financial data. The application requires users to have a
An analyst is evaluating the security of a web application that does not hold sensitive or financial data. The application requires users to have a minimum password length of characters. One of the characters must be capitalized, and one must be a number. To reset the password, the user is asked to provide the birthplace, birthdate, and mother's maiden name. When all of these are entered correctly, a new password is emailed to the user. Which of the following should concern the analyst the MOST?
A The security answers may be determined via online reconnaissance.
B The password is too long, which may encourage users to write the password down.
C The password should include a special character.
D The minimum password length is too short.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
