Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company's security audit reveals that several employees are using weak passwords that can be easily guessed. The current password policy requires a minimum of 8 characters but does not enforce complexity. Which change to the password policy would be MOST effective in increasing security against brute-force attacks?

⚠ Common exam trap

It's easy for candidates to assume complexity (mixing character types) is the primary defense against brute-force, but the CompTIA 220-1102 exam emphasizes that increasing length provides a far greater exponential increase in security than complexity, which only adds a linear or small multiplicative factor to the keyspace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase minimum password length to 12 characters

Increasing the minimum password length to 12 characters is the most effective measure against brute-force attacks because it exponentially expands the keyspace. A brute-force attack tries every possible combination; each additional character multiplies the number of possible passwords by the size of the character set (e.g., 95 printable ASCII characters). Moving from 8 to 12 characters increases the total combinations from 95^8 to 95^12, making the attack computationally infeasible in a reasonable timeframe, even without complexity requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Increase minimum password length to 12 characters

    Why this is correct

    Longer passwords increase the search space exponentially, greatly improving resistance to brute-force attacks. Each additional character multiplies the number of possible combinations by the size of the character set (e.g., 95 printable ASCII characters), so a 12-character password has 95^12 possibilities, making exhaustive offline cracking computationally infeasible. Length is the dominant factor in password entropy, and it directly counteracts both brute-force and dictionary attacks.

  • ✗

    Require a mix of uppercase, lowercase, numbers, and special characters

    Why it's wrong here

    Complexity increases entropy but not as much as increasing length; length is more effective against brute-force. Adding character types only raises the effective character set size from 26 to roughly 95, which adds a small logarithmic factor to the search space, whereas each extra character multiplies it by the entire set size. Furthermore, users commonly respond to complexity rules with predictable substitutions like "Password1!", which actually lowers resistance to dictionary attacks.

  • ✗

    Implement account lockout after 3 failed attempts

    Why it's wrong here

    Account lockout prevents online brute-force but does not protect against offline attacks on password hashes. If an attacker has exfiltrated the password hash database, they can crack hashes at their own pace using GPU clusters or cloud servers, with no lockout threshold applied. Lockout only throttles interactive login attempts against the live service and can be bypassed via distributed low-rate attacks or by targeting different accounts.

  • ✗

    Force password change every 30 days

    Why it's wrong here

    Frequent changes often lead to weaker, easily guessable passwords or reuse, reducing security. Under a 30-day expiry, users tend to select simpler base words and make predictable variants (e.g., "Summer2023!" to "Summer2023?2"), which are easily cracked by targeted mutation rules. Rapid rotation also encourages insecure storage, such as written notes or digital sticky notes. Modern guidance from NIST 800-63B recommends eliminating arbitrary periodic expiration unless there is evidence of compromise, because the security cost outweighs the benefit.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.