220-1102 Security Practice Question
A security audit reveals that many user passwords are being cracked using offline brute-force attacks. The current password policy requires a minimum of 8 characters with uppercase, lowercase, and numbers. Which configuration change would MOST significantly increase resistance to brute-force password cracking?
⚠ Common exam trap
A common mix-up: candidates confuse online brute-force defenses (account lockout) with offline brute-force resistance (password entropy), or they overestimate the impact of special characters compared to length, which is the primary driver of keyspace expansion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the minimum password length to 14 characters.
Increasing the minimum password length to 14 characters exponentially expands the keyspace for brute-force attacks. Each additional character multiplies the number of possible combinations by the character set size (e.g., 95 printable ASCII characters), making offline cracking computationally infeasible even with high-speed GPUs. This directly addresses the attack vector by raising the entropy far beyond what current hardware can exhaust in a reasonable timeframe.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increase the minimum password length to 14 characters.
Why this is correct
Increasing the minimum password length to 14 characters multiplies the keyspace exponentially with each additional character position. For example, a 14-character password using a 62-character alphabet (upper, lower, digits) has 62^14 ≈ 10^25 combinations, which is astronomically larger than any 8-character password with special characters (≈10^16 for 94^8). Even a slightly shorter password, regardless of its character diversity, can be cracked far faster by modern GPU-based hash-cracking tools, so this policy directly frustrates offline brute-force attacks.
- ✗
Require at least one special character.
Why it's wrong here
Requiring at least one special character expands the effective character set by only a few dozen symbols, which adds roughly 6 bits of entropy for a short password—hardly more than adding a single extra character. Users also tend to satisfy the requirement by appending a predictable symbol such as "!" to the end, so the actual strength gain is minimal. This policy does not mandate a longer string, leaving short, low-entropy passwords vulnerable to offline hash-cracking despite the superficial complexity.
- ✗
Enforce a password history of 24 previous passwords.
Why it's wrong here
Enforcing a password history of 24 previous passwords simply stops users from immediately cycling back to an old secret during a password change. It has no influence on an attacker who already possesses a cracked password hash or a stolen credential from a previous breach; the attacker can still reuse that password to log in and the user could have created a weak, easily crackable password the first time. History is purely a preference/reuse control, not a cryptographic-strength mitigation for offline hash-cracking.
- ✗
Implement an account lockout policy after 3 failed attempts.
Why it's wrong here
An account lockout policy after 3 failed attempts limits the rate of online guesses against a live login interface, but it does nothing to hinder offline attacks after an attacker has extracted the password hash database. Once the hashes are stolen, the attacker can run billions of guesses per second on their own hardware without ever hitting the lockout threshold. Worse, aggressive lockout can be weaponized to deny service to legitimate users by repeatedly failing authentication on their accounts, making it a poor answer to a hash-cracking audit finding.
Go deeper
Related to this question
Learn chapter
VPN Client Configuration
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Password policy
A set of rules designed to enhance computer security by encouraging users to create strong, secure passwords and store them properly.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's security audit reveals that several employees are using weak passwords that can be easily guessed. The current password policy requires a minimum of 8 characters but does not enforce complexity. Which change to the password policy would be MOST effective in increasing security against brute-force attacks?
medium- ✓ A.Increase minimum password length to 12 characters
- B.Require a mix of uppercase, lowercase, numbers, and special characters
- C.Implement account lockout after 3 failed attempts
- D.Force password change every 30 days
Why A: Increasing the minimum password length to 12 characters is the most effective measure against brute-force attacks because it exponentially expands the keyspace. A brute-force attack tries every possible combination; each additional character multiplies the number of possible passwords by the size of the character set (e.g., 95 printable ASCII characters). Moving from 8 to 12 characters increases the total combinations from 95^8 to 95^12, making the attack computationally infeasible in a reasonable timeframe, even without complexity requirements.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.