Question

You want to be sure that if somebody is trying to guess one of your user's passwords, the account will be locked out after 4 unsuccessful password entries. Furthermore, you want the account to be locked out for one hour before it automatically unlocks. The count of unsuccessful attempts should be reset after 20 minutes. What account lockout policies should you set and with what values?

Answer

This answer is hidden. It contains 96 characters.