220-1102 Security Practice Question
A company's security audit reveals that several employees are using weak passwords that can be easily guessed. The current password policy requires a minimum of 8 characters but does not enforce complexity. Which change to the password policy would be MOST effective in increasing security against brute-force attacks?
⚠ Common exam trap
It's easy for candidates to assume complexity (mixing character types) is the primary defense against brute-force, but the CompTIA 220-1102 exam emphasizes that increasing length provides a far greater exponential increase in security than complexity, which only adds a linear or small multiplicative factor to the keyspace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase minimum password length to 12 characters
Increasing the minimum password length to 12 characters is the most effective measure against brute-force attacks because it exponentially expands the keyspace. A brute-force attack tries every possible combination; each additional character multiplies the number of possible passwords by the size of the character set (e.g., 95 printable ASCII characters). Moving from 8 to 12 characters increases the total combinations from 95^8 to 95^12, making the attack computationally infeasible in a reasonable timeframe, even without complexity requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increase minimum password length to 12 characters
Why this is correct
Longer passwords increase the search space exponentially, greatly improving resistance to brute-force attacks. Each additional character multiplies the number of possible combinations by the size of the character set (e.g., 95 printable ASCII characters), so a 12-character password has 95^12 possibilities, making exhaustive offline cracking computationally infeasible. Length is the dominant factor in password entropy, and it directly counteracts both brute-force and dictionary attacks.
- ✗
Require a mix of uppercase, lowercase, numbers, and special characters
Why it's wrong here
Complexity increases entropy but not as much as increasing length; length is more effective against brute-force. Adding character types only raises the effective character set size from 26 to roughly 95, which adds a small logarithmic factor to the search space, whereas each extra character multiplies it by the entire set size. Furthermore, users commonly respond to complexity rules with predictable substitutions like "Password1!", which actually lowers resistance to dictionary attacks.
- ✗
Implement account lockout after 3 failed attempts
Why it's wrong here
Account lockout prevents online brute-force but does not protect against offline attacks on password hashes. If an attacker has exfiltrated the password hash database, they can crack hashes at their own pace using GPU clusters or cloud servers, with no lockout threshold applied. Lockout only throttles interactive login attempts against the live service and can be bypassed via distributed low-rate attacks or by targeting different accounts.
- ✗
Force password change every 30 days
Why it's wrong here
Frequent changes often lead to weaker, easily guessable passwords or reuse, reducing security. Under a 30-day expiry, users tend to select simpler base words and make predictable variants (e.g., "Summer2023!" to "Summer2023?2"), which are easily cracked by targeted mutation rules. Rapid rotation also encourages insecure storage, such as written notes or digital sticky notes. Modern guidance from NIST 800-63B recommends eliminating arbitrary periodic expiration unless there is evidence of compromise, because the security cost outweighs the benefit.
Go deeper
Related to this question
Learn chapter
Vishing and Smishing Attacks
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.