This comes dangerously close to this one:
https://www.portcullis-security.com/security-research-and-do...
Very user-friendly, but not exactly secure. Each bit of information you volunteer to unauthorized user reduces the work the attacker has to do to gain access.
As for "how many expected" - limiting the password length is not exactly a good idea in any case.