200-201 Security Policies and Procedures Practice Question
A security analyst is reviewing the organization's password policy, which currently requires a minimum of eight characters with complexity but no expiration. After a recent audit finding, management wants to align with modern best practices. Which change should the analyst recommend?
⚠ Common exam trap
The trap here is assuming that frequent password expiration improves security, when it often leads to weaker, predictable passwords and is no longer recommended.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the minimum length to 14 characters and remove forced periodic expiration
Modern password guidance recommends longer minimum lengths, such as 14 characters, and discourages forced periodic expiration unless compromise is suspected. Longer passwords increase the effort required for brute-force attacks, while removing arbitrary expiration reduces predictable user behavior. This combination addresses the audit finding by aligning the policy with current best practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow users to choose any password of any length as long as it contains a special character
Why it's wrong here
This is incorrect because removing length requirements while only requiring a special character allows very weak passwords such as 'a!'. Length is the most significant factor in password strength. Modern guidance emphasizes minimum length and screening against breached password lists, not just character composition. This option would not satisfy the audit finding or improve security.
- ✗
Reduce the minimum length to six characters and require changes every 30 days
Why it's wrong here
This is incorrect because shorter passwords and frequent changes weaken security. Users tend to create predictable variations such as adding a number or incrementing a month, which attackers easily anticipate. Reducing length also lowers the keyspace, making brute-force attacks more feasible. This recommendation contradicts modern best practices and would worsen the audit finding.
- ✗
Require passwords to be changed every 60 days and prohibit reuse of the last 24 passwords
Why it's wrong here
This is incorrect because forced periodic expiration is now discouraged unless there is evidence of compromise. Frequent changes encourage weak patterns and increase help desk load. While password history can prevent immediate reuse, it does not address the core issue that expiration policies often reduce rather than improve security. The scenario seeks alignment with modern best practices.
- ✓
Increase the minimum length to 14 characters and remove forced periodic expiration
Why this is correct
This is correct because modern guidance favors longer passwords or passphrases over frequent forced changes, which often lead to predictable increments. A 14-character minimum significantly increases resistance to brute-force and credential-stuffing attacks. Removing expiration aligns with NIST guidance that discourages arbitrary rotation, reducing user frustration and weak password patterns.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.