Which of the following is the best practice for creating strong passwords?
Trap 1: Use your birthday and pet's name
Birthdays and pet names are widely discoverable through social media and public records, so they fall to dictionary and targeted guessing attacks. It tempts because such details are memorable and need no manager, which suits low-risk throwaway accounts; strong passwords instead require length and unpredictability.
Trap 2: Use a common phrase with numbers replacing letters
Substituting digits for letters (for example, p4ssw0rd) follows a predictable pattern that cracking tools and rule-based dictionaries already encode, so entropy barely rises. It tempts because the result looks complex and stays memorable; genuinely strong passphrases avoid such systematic leetspeak substitutions.
Trap 3: Use the same password for all accounts but change it monthly
Reusing one password across accounts means a single breach exposes every account, and monthly rotation does nothing to contain that blast radius. It tempts because it reduces memorisation effort and rotation appears diligent; unique credentials per account with a password manager, plus MFA, is the actual practice.
- A
Use your birthday and pet's name
Why it fails: Birthdays and pet names are widely discoverable through social media and public records, so they fall to dictionary and targeted guessing attacks. It tempts because such details are memorable and need no manager, which suits low-risk throwaway accounts; strong passwords instead require length and unpredictability.
- B
Use a common phrase with numbers replacing letters
Why it fails: Substituting digits for letters (for example, p4ssw0rd) follows a predictable pattern that cracking tools and rule-based dictionaries already encode, so entropy barely rises. It tempts because the result looks complex and stays memorable; genuinely strong passphrases avoid such systematic leetspeak substitutions.
- C
Use a random combination of uppercase, lowercase, numbers, and symbols of at least 12 characters
Length plus character diversity maximises the search space an attacker must exhaust, making brute-force and dictionary attacks impractical. Twelve characters mixing uppercase, lowercase, numbers and symbols satisfies this, whereas shorter or single-character-class passwords fall quickly to cracking.
- D
Use the same password for all accounts but change it monthly
Why it fails: Reusing one password across accounts means a single breach exposes every account, and monthly rotation does nothing to contain that blast radius. It tempts because it reduces memorisation effort and rotation appears diligent; unique credentials per account with a password manager, plus MFA, is the actual practice.