200-201 Security Policies and Procedures Practice Question
A security analyst is reviewing the organization's password policy. The policy currently requires passwords to be at least 8 characters and changed every 60 days. The analyst recommends aligning with NIST SP 800-63B guidelines. Which change should the analyst recommend?
⚠ Common exam trap
The trap here is assuming that frequent password changes and complexity requirements are always more secure, when NIST guidelines actually discourage them in favor of length and breach checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the periodic password expiration and instead enforce a longer minimum length with a blocklist of common passwords.
The analyst should recommend removing periodic password expiration and instead enforcing a longer minimum length with a blocklist of common passwords. NIST SP 800-63B emphasizes that password expiration can degrade security by encouraging weak, predictable passwords. A blocklist prevents users from choosing easily guessed or compromised passwords, and a longer minimum length increases resistance to brute-force attacks. This approach aligns with modern best practices and reduces the burden on users and help desk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the minimum password length to 12 characters and require complexity.
Why it's wrong here
NIST SP 800-63B recommends a minimum of 8 characters and does not require complexity rules like mixing uppercase, lowercase, numbers, and symbols. While longer passwords can be beneficial, mandating complexity often leads to predictable patterns and increased help desk calls. The guideline focuses on length and checking against breached passwords, not on imposing composition rules. Therefore, this change is not aligned with NIST recommendations.
- ✓
Remove the periodic password expiration and instead enforce a longer minimum length with a blocklist of common passwords.
Why this is correct
NIST SP 800-63B advises against arbitrary password expiration because it leads to weaker passwords and user frustration. Instead, it recommends a minimum length of 8 characters (preferably more) and checking new passwords against a list of compromised or common passwords. This approach improves security by preventing easily guessed passwords and reducing the need for frequent changes, which often result in incremental variations that attackers can predict.
- ✗
Require passwords to be changed every 30 days to reduce the window of compromise.
Why it's wrong here
Frequent password changes, such as every 30 days, are explicitly discouraged by NIST SP 800-63B. Users tend to create passwords that are easy to remember and incrementally change them, making them easier to guess. Short expiration periods also increase the risk of users writing down passwords or reusing them across systems. The guideline recommends against arbitrary expiration and instead focuses on other measures like length and breach checks.
- ✗
Implement a requirement for passwords to include at least one special character and one number.
Why it's wrong here
NIST SP 800-63B does not mandate composition rules such as requiring special characters or numbers. Such rules can lead to predictable substitutions (e.g., 'P@ssw0rd') and do not significantly improve security. The guideline emphasizes length and screening against breached password lists. While special characters can increase entropy, they are not a recommended requirement under the updated guidelines, so this change would not align with NIST.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.