FC0-U71 Security Practice Question
Which THREE of the following are best practices for password security?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enabling two-factor authentication where possible
Option B is correct because enabling two-factor authentication (2FA) adds a second verification factor (e.g., TOTP, hardware token, or push notification) beyond the password, so a stolen or guessed password alone is insufficient to compromise the account. Option C is correct because a password manager generates high-entropy, unique credentials for each site and stores them encrypted (typically under AES-256 with a master passphrase), eliminating weak or reused passwords and reducing the risk of credential-stuffing attacks. Option E is correct because length and character diversity increase the search space, making brute-force and dictionary attacks computationally impractical; 12+ characters mixing uppercase, lowercase, digits, and symbols aligns with NIST and common policy guidance for strong passwords. Option A is wrong because sharing passwords destroys individual accountability and non-repudiation, and violates least-privilege and audit principles; use delegated accounts or role-based access instead. Option D is wrong because reusing one password across sites means a single breach exposes all accounts via credential stuffing, so every account should have a unique password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sharing passwords with trusted coworkers when necessary
Why it's wrong here
Sharing credentials destroys individual accountability and non-repudiation, and any coworker who later leaves retains access, so it is never a best practice. It is tempting when a colleague needs urgent cover, but the correct approach is issuing separate accounts with delegated permissions or a shared privileged-access vault.
- ✓
Enabling two-factor authentication where possible
Why this is correct
Enabling two-factor authentication adds a second verification factor beyond the password, so a stolen or guessed credential alone cannot grant access. This directly satisfies the stem's password-security best-practise requirement by mitigating credential compromise, and Microsoft Entra ID supports it natively through Conditional Access and authentication methods policies.
- ✓
Using a password manager to generate and store passwords
Why this is correct
A password manager generates long, random, unique credentials per site and stores them encrypted, eliminating password reuse and weak, memorable passwords. This directly addresses the credential-guessing and breach-reuse risks that password security best practices target.
- ✗
Reusing the same password across multiple sites
Why it's wrong here
Reuse means a breach on one site exposes credentials everywhere, defeating the containment that unique passwords provide. It is tempting because it reduces memorisation effort and login friction, and it would suit low-risk throwaway accounts where no sensitive data or shared identity is involved.
- ✓
Using a password with at least 12 characters including uppercase, lowercase, numbers, and symbols
Why this is correct
Length and character-class complexity directly increase the search space an attacker must exhaust, defeating brute-force and dictionary attacks. Twelve characters mixing upper, lower, numeric and symbol sets satisfies the stem's best-practise requirement by maximising entropy per credential.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.