FC0-U71 Security Practice Question
A new employee at a software company receives a laptop and must follow the organization's security policy when choosing credentials and handling them day to day. Which TWO of the following practices align with standard authentication security guidance? (Choose two.)
⚠ Common exam trap
The trap here is treating a long passphrase as automatically safe, when reusing it across accounts still lets one breach compromise every system that shares it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a unique passphrase for each work account rather than reusing one password everywhere
Sound credential practice combines unique secrets per account with a second authentication factor. Unique passphrases contain the blast radius of any single breach, and multifactor authentication ensures a stolen password alone cannot grant access. Shared spreadsheets, sticky notes, and password reuse all weaken authentication by exposing or duplicating secrets, so they fail the policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using a unique passphrase for each work account rather than reusing one password everywhere
Why this is correct
Unique credentials per account limit the damage of a breach: if one service is compromised, attackers cannot replay the same password against the employee's other work systems. This directly reduces credential-stuffing risk and is a foundational authentication practice, making it a correct choice for the policy the new employee must follow.
- ✗
Storing passwords in a shared spreadsheet on the team's network drive so coworkers can cover for absences
Why it's wrong here
A shared spreadsheet exposes every credential to anyone with drive access and provides no accountability for who used which password. It also defeats the purpose of unique accounts, since actions cannot be traced to an individual. This practice increases risk and violates least-privilege and non-repudiation expectations, so it is not acceptable guidance.
- ✓
Enabling multifactor authentication on the company email and code repository accounts
Why this is correct
Multifactor authentication requires something beyond a password, such as a code from an authenticator app, so a stolen password alone is insufficient to log in. Applying it to high-value accounts like email and source code repositories blocks many account-takeover attempts and is explicitly recommended by authentication guidance, making this a correct practice.
- ✗
Reusing the same long passphrase across all work accounts because it is easier to remember
Why it's wrong here
Reuse means a single breach at any one service exposes every other account using that passphrase, a risk attackers exploit through credential stuffing. Length alone does not offset the danger when the same secret guards email, repositories, and administrative tools. Standard guidance calls for unique credentials per account, so this practice is incorrect.
- ✗
Writing the passphrase on a sticky note attached under the laptop keyboard for quick reference
Why it's wrong here
Physically recording a passphrase near the device lets anyone with brief access to the laptop obtain the credential, including visitors or cleaning staff. It undermines the secrecy that authentication depends on and turns a strong passphrase into an easily discovered secret, so it contradicts standard credential-handling guidance and should not be followed.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.