hardMultiple SelectObjective-mapped
Secure Password Policy Best Practices
Which THREE of the following are best practices for creating secure passwords?
Quick Answer
The answer is to include a mix of uppercase, lowercase, numbers, and symbols, as this dramatically increases the password’s entropy, making it exponentially harder for brute-force or dictionary attacks to succeed. This complexity expands the character set from 26 letters to 95 possible characters per position, creating billions of additional combinations that an attacker must test. On the CompTIA ITF+ FC0-U61 exam, this concept appears in the security domain, often paired with a common trap where test-takers mistakenly select “use personal information” or “keep the same password forever” as best practices. A frequent memory tip is to think of password strength like a lock: the more varied the tumblers (character types), the harder it is to pick. For the exam, remember the acronym “UNCS” — Uppercase, Numbers, lowercase, Symbols — to recall the four required elements of a truly secure password policy.
⚠ Common exam trap
CompTIA often tests the misconception that password reuse is acceptable for memorability, but security best practices require unique passwords per account to prevent credential stuffing attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change password every 90 days
Regular password changes (e.g., every 90 days) limit the window of exposure if a password is compromised. This practice aligns with NIST SP 800-63B guidelines, which recommend periodic rotation to mitigate risks from credential theft or brute-force attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the same password for all accounts for memorability
Why it's wrong here
Reusing passwords increases risk if one account is compromised.
- ✓
Change password every 90 days
Why this is correct
Regular changes limit the window of exposure if stolen.
- ✓
Use at least 8 characters
Why this is correct
Longer passwords are harder to crack.
- ✗
Use personal information like birthdate
Why it's wrong here
Personal info is easy to guess or obtain via social engineering.
- ✓
Include a mix of uppercase, lowercase, numbers, symbols
Why this is correct
Diverse character sets increase complexity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on FC0-U71
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are best practices for creating and managing passwords?
easy- A.Share passwords with colleagues in the same department to improve collaboration
- B.Reuse passwords every 90 days
- ✓ C.Enable multi-factor authentication where available
- ✓ D.Use a unique password for each online account
- E.Write down passwords on a sticky note and keep it near the computer
Why C: Options C and D are correct. Enabling multi-factor authentication adds an extra layer of security beyond just a password, making it much harder for attackers to gain access. Using a unique password for each online account prevents a single breach from compromising multiple accounts. Option A is wrong because sharing passwords undermines accountability and security. Option B is wrong because reusing passwords, even if changed every 90 days, is still poor practice; the best practice is to use unique passwords and not reuse them. Option E is wrong because writing down passwords near the computer exposes them to theft.
Variation 2. A company requires all employees to use strong passwords. Which of the following password policies best aligns with security best practices?
medium- A.Passwords must be changed every 30 days but can be simple.
- ✓ B.Passwords must be at least 8 characters and include uppercase, lowercase, numbers, and symbols.
- C.Passwords must be the same across all corporate accounts for consistency.
- D.Passwords must be a minimum of 6 characters and contain only letters.
Why B: It enforces complexity requirements (uppercase, lowercase, numbers, symbols) and a minimum length of 8 characters, which aligns with NIST SP 800-63B guidelines and modern security best practices. Complex passwords resist brute-force and dictionary attacks by increasing the keyspace exponentially. Simple passwords, even if changed frequently, remain vulnerable to guessing and credential stuffing.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.