Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company's password policy requires complex passwords changed every 30 days. Users frequently write their passwords on sticky notes. Which security enhancement would BEST reduce the risk of password compromise?

⚠ Common exam trap

CompTIA often tests the misconception that strengthening password policies (length, history, or change frequency) is the best solution for human behavior issues like writing down passwords, when in fact MFA directly addresses the compromise risk regardless of password storage practices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement multi-factor authentication (MFA).

Multi-factor authentication (MFA) adds an additional layer of security beyond the password, such as a one-time code from an authenticator app or a biometric factor. Even if a user writes down their password and it is stolen, the attacker cannot authenticate without the second factor. This directly mitigates the risk of password compromise from sticky notes, whereas password policy changes alone do not address the root cause of poor password storage habits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement multi-factor authentication (MFA).

    Why this is correct

    MFA adds an additional layer of security, such as a biometric or TOTP token, so that possession of the password alone is insufficient for authentication. Even if an employee writes down their password and it is stolen or observed, the attacker still lacks the required second factor, such as a fingerprint or a rotating code from an authenticator app. This directly neutralizes the risk posed by physically recorded credentials and is the most effective compensating control for this scenario.

  • ✗

    Increase the minimum password length to 15 characters.

    Why it's wrong here

    Increasing the minimum password length to 15 characters raises entropy and makes brute-force or offline cracking more difficult, but it does nothing to prevent the root cause of users committing passwords to written media. A 15-character password can be just as easily written on a sticky note or saved in an unencrypted file, and that physical exposure bypasses any algorithmic strength. In fact, longer passwords may be harder to memorize, increasing the likelihood that users will store them insecurely rather than reducing it.

  • ✗

    Reduce the password change frequency to every 90 days.

    Why it's wrong here

    Reducing the password change frequency to every 90 days lowers the administrative burden and can curb users' tendency to tack numbers onto a familiar base, but it does not stop the physical act of writing down the current password. More importantly, if a written password is stolen, a longer validity period actually extends the time an intruder can silently reuse it before the password rotates. This option treats user frustration as the problem, whereas the actual vulnerability is the unprotected written credential itself.

  • ✗

    Require a password history of 24 previous passwords.

    Why it's wrong here

    Requiring a password history of 24 previous passwords forces users to generate a genuinely new password each time, preventing reuse of credentials that may have been exposed in prior breaches or handwritten logs. However, it provides no protection against the current password being written down, and it cannot revoke or invalidate a stolen password that is still valid. Worse, a strict history may drive users to cascade the new password into the same insecure note-taking habit, perpetuating the exact behavior the company wants to eliminate.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.