FC0-U71 Security Practice Question
Which of the following is a best practice for creating a strong password?
⚠ Common exam trap
FC0-U71 often tests the misconception that complexity alone (like 8 characters with letters and numbers) is sufficient for a strong password, when in fact length and uniqueness are more critical.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a long passphrase that includes symbols and numbers
A long passphrase that includes symbols and numbers is considered a best practice because it increases both length and complexity, making it significantly harder for attackers to crack using brute-force or dictionary attacks. Length is the most critical factor in password strength, and adding symbols and numbers further expands the search space. This approach aligns with guidance from NIST and other security organizations, which recommend passphrases over short, complex passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using a long passphrase that includes symbols and numbers
Why this is correct
Length defeats brute-force and dictionary attacks far more effectively than complexity alone, while mixing symbols and numbers widens the search space. A passphrase remains memorable yet resists guessing, satisfying the best-practice requirement without relying on predictable substitutions or reused credentials.
- ✗
Using a password with 8 characters including letters and numbers
Why it's wrong here
Eight characters mixing letters and numbers is short enough for brute-force and dictionary attacks to crack quickly; length and unpredictability matter. It is tempting because it satisfies many legacy complexity policies, and would be correct only where a system enforces that minimum and nothing stronger.
- ✗
Reusing the same password across multiple sites
Why it's wrong here
Reusing the same password across multiple sites violates the principle of credential isolation; if one site suffers a data breach, attackers can use the stolen password to compromise all other accounts where it is reused. This practice is tempting because it simplifies memorisation and login speed, and it would be acceptable only if every site used a separate, unique password—never the same one.
- ✗
Using your pet's name as a password
Why it's wrong here
A pet's name is a dictionary word easily guessed from social media or personal knowledge, so it fails unpredictability. It is tempting because it is memorable and avoids writing passwords down, and would be correct only if combined with substantial random padding and unique per account.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.