220-1102 Security Practice Question
A company's current password policy requires a minimum of 14 characters with complexity (uppercase, lowercase, numbers, and special characters). Users frequently forget these complex passwords and submit help desk reset requests. Which alternative approach would BEST enhance security while reducing the burden on users?
⚠ Common exam trap
Test-takers frequently assume shorter passwords with complexity are more secure than longer passphrases, but CompTIA tests the understanding that length trumps complexity for entropy and usability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow users to use passphrases instead of complex passwords
Passphrases (e.g., 'Blue-Coffee-Jump-7!') are longer yet easier to remember than complex passwords. They increase entropy and resistance to brute-force attacks while reducing help desk calls, directly addressing the user burden. NIST SP 800-63B recommends passphrases over arbitrary complexity rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allow users to use passphrases instead of complex passwords
Why this is correct
Passphrases are a superior alternative because they leverage length, not forced character variety, to defeat brute-force and dictionary attacks. NIST SP 800-63B explicitly recommends allowing passphrases of 15+ characters, as a longer memorable phrase provides far more entropy than an 8-character mix of symbols, digits, and uppercase letters. This option directly reduces complexity-based resistance while improving memorability, thereby solving the stated policy problem without sacrificing security.
- ✗
Reduce the minimum password length to 8 characters to make passwords easier to type
Why it's wrong here
Reducing the minimum length from 14 to 8 characters would exponentially shrink the keyspace, since each additional character multiplies the possible combinations by the character set size (e.g., 95^6 difference). Modern GPU-based cracking tools can exhaust an 8-character mixed character space in minutes or hours, making this a severe security downgrade. While shorter passwords are easier to type, the convenience gain cannot justify the dramatic increase in successful offline brute-force and rainbow-table attacks.
- ✗
Enforce password expiration every 30 days
Why it's wrong here
Forcing password changes every 30 days does not increase security; it actually encourages users to make predictable, incremental modifications (e.g., 'Password1!', 'Password2!') and to write their passwords down, because the churn is unsustainable. NIST SP 800-63B now advises against arbitrary periodic expiration, noting that frequent resets lead to weaker passwords and higher helpdesk costs, and that the perceived benefit of reducing exposure is marginal compared to the risks of user workarounds.
- ✗
Implement single sign-on with smart cards and PINs
Why it's wrong here
Smart-card and PIN single sign-on delivers hardware-backed multi-factor authentication, but it does not alter the underlying password complexity requirement for the account itself—it merely adds a second possession factor. Deploying such an infrastructure demands costly card readers, certificate revocation handling, and enrollment procedures, while failing to address the core issue of user-created weak passwords. This option is an over-engineered workaround that adds expense and operational complexity without easing the difficulty users face in creating and remembering compliant passwords.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Password policy
A set of rules designed to enhance computer security by encouraging users to create strong, secure passwords and store them properly.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's password policy requires a minimum length of 14 characters with complexity (uppercase, lowercase, numbers, and special characters). Users find these passwords difficult to remember and frequently reset them. Which alternative approach would BEST enhance security while reducing the user burden?
hard- ✓ A.Implement a passphrase policy that allows spaces and longer combinations of common words.
- B.Require the use of a password manager and enable single sign-on for all applications.
- C.Reduce the minimum password length to 8 characters while enforcing standard complexity requirements.
- D.Replace passwords with biometric authentication, such as fingerprint or facial recognition.
Why A: Passphrases leverage length over complexity to enhance security. A passphrase of a few common words (e.g., 'correct horse battery staple') provides high entropy (approximately 2^44 for a 4-word passphrase from a 2048-word list) while being far easier for users to remember than a 14-character random string. This reduces password reset frequency and improves overall security posture by making brute-force and dictionary attacks computationally infeasible.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.