220-1102 Security Practice Question
Which of the following passwords is considered the strongest according to standard security best practices?
⚠ Common exam trap
The 220-1102 exam often tests the misconception that including a number or a special character alone makes a password strong, when in reality length and unpredictability (avoiding common words, dates, or patterns) are more critical for security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tr0ub4dor&3
'Tr0ub4dor&3', is the strongest because it combines uppercase letters, lowercase letters, numbers, and a special character (&) in a length of 11 characters, which resists brute-force and dictionary attacks far better than shorter or simpler passwords. Standard security best practices (e.g., NIST SP 800-63B) recommend passwords with complexity and length, and this option meets those criteria without relying on common patterns or dictionary words.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password123
Why it's wrong here
Password123 contains the dictionary word 'Password' appended by the sequential digits 123, and it lacks any special character. This is a classic example of a 'base word + digits' formula, making it immediately recognizable to both password-cracking dictionaries and credential-stuffing lists. Its uppercase P does little to offset the predictability, as the structure and content appear in virtually every leaked password corpus.
- ✗
12345abcdef
Why it's wrong here
12345abcdef is built entirely from two ascending sequences—12345 and abcdef—and contains no uppercase letter or symbol. The monotonically increasing patterns create an identifiable keyboard/order mask, so an offline brute-force or rule-based attack can crack it quickly with minimal guesses. It also has zero dictionary-resistant randomness, leaving each character highly correlated with the neighboring characters.
- ✓
Tr0ub4dor&3
Why this is correct
This password is 11 characters long, includes uppercase (T), lowercase (r, o, u, b, d, o, r), numbers (0, 4, 3), and a symbol (&). It is not a dictionary word and has good variety.
- ✗
Summer2024!
Why it's wrong here
Summer2024! uses a capital S and an exclamation point, but the core token is a common season spelled in plain text plus the current year. Attackers frequently build 'season + year + symbol' patterns into targeted wordlists because people anthropomorphize dates. Since Summer and 2024 are both contextually guessable from calendar awareness, the added symbol raises entropy only slightly and does not prevent pattern-based or hybrid dictionary attacks.
Go deeper
Related to this question
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.