Courseiva
Security →mediumMultiple Select

FC0-U71 Security Practice Question

A new employee at a software company receives a laptop and must follow the organization's security policy when choosing credentials and handling them day to day. Which TWO of the following practices align with standard authentication security guidance? (Choose two.)

⚠ Common exam trap

The trap here is treating a long passphrase as automatically safe, when reusing it across accounts still lets one breach compromise every system that shares it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a unique passphrase for each work account rather than reusing one password everywhere

Sound credential practice combines unique secrets per account with a second authentication factor. Unique passphrases contain the blast radius of any single breach, and multifactor authentication ensures a stolen password alone cannot grant access. Shared spreadsheets, sticky notes, and password reuse all weaken authentication by exposing or duplicating secrets, so they fail the policy requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using a unique passphrase for each work account rather than reusing one password everywhere

    Why this is correct

    Unique credentials per account limit the damage of a breach: if one service is compromised, attackers cannot replay the same password against the employee's other work systems. This directly reduces credential-stuffing risk and is a foundational authentication practice, making it a correct choice for the policy the new employee must follow.

  • ✗

    Storing passwords in a shared spreadsheet on the team's network drive so coworkers can cover for absences

    Why it's wrong here

    A shared spreadsheet exposes every credential to anyone with drive access and provides no accountability for who used which password. It also defeats the purpose of unique accounts, since actions cannot be traced to an individual. This practice increases risk and violates least-privilege and non-repudiation expectations, so it is not acceptable guidance.

  • ✓

    Enabling multifactor authentication on the company email and code repository accounts

    Why this is correct

    Multifactor authentication requires something beyond a password, such as a code from an authenticator app, so a stolen password alone is insufficient to log in. Applying it to high-value accounts like email and source code repositories blocks many account-takeover attempts and is explicitly recommended by authentication guidance, making this a correct practice.

  • ✗

    Reusing the same long passphrase across all work accounts because it is easier to remember

    Why it's wrong here

    Reuse means a single breach at any one service exposes every other account using that passphrase, a risk attackers exploit through credential stuffing. Length alone does not offset the danger when the same secret guards email, repositories, and administrative tools. Standard guidance calls for unique credentials per account, so this practice is incorrect.

  • ✗

    Writing the passphrase on a sticky note attached under the laptop keyboard for quick reference

    Why it's wrong here

    Physically recording a passphrase near the device lets anyone with brief access to the laptop obtain the credential, including visitors or cleaning staff. It undermines the secrecy that authentication depends on and turns a strong passphrase into an easily discovered secret, so it contradicts standard credential-handling guidance and should not be followed.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.