Courseiva
Security →hardMultiple Select

FC0-U71 Security Practice Question

Which THREE of the following are characteristics of a strong password? (Select THREE)

⚠ Common exam trap

The trap here is that candidates may select 'includes the user's birth date' thinking personalization adds security, or miss that 'unique and not reused' is a strength characteristic rather than a convenience feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

At least 12 characters in length

Option A is correct because a minimum length of at least 12 characters increases the search space an attacker must cover in a brute-force or dictionary attack, making the password substantially harder to crack. Option B is correct because mixing uppercase letters, lowercase letters, numbers, and symbols expands the character set and defeats simple dictionary and pattern-based guessing techniques. Option D is correct because using a unique password that is not reused on other accounts prevents credential-stuffing attacks, where a breach of one service would otherwise compromise multiple accounts. Option C is incorrect because including a user's birth date creates a predictable, easily guessable value often obtainable from social media or public records. Option E is incorrect because reusing a password across multiple accounts is a dangerous practice that amplifies the impact of any single credential leak.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    At least 12 characters in length

    Why this is correct

    A 12-character minimum directly increases the search space an attacker must exhaust, making brute-force and hash-cracking attacks computationally impractical. Length is the dominant factor in password entropy, so this satisfies the stem's requirement for a strong-password characteristic, independent of complexity rules or composition.

  • ✓

    Contains uppercase, lowercase, numbers, and symbols

    Why this is correct

    Mixing uppercase, lowercase, digits and symbols satisfies the complexity requirement by expanding the character set, which increases the search space an attacker must exhaust during brute-force or dictionary attacks. This directly meets the stem's demand for a strong password characteristic, since length alone is insufficient without varied character classes.

  • ✗

    Includes the user's birth date

    Why it's wrong here

    A birth date is guessable personal information, reducing entropy and enabling targeted guessing or social-engineering attacks. Strong passwords avoid publicly discoverable details. Birth dates belong in account recovery or identity verification contexts, not password composition, where unpredictability and length are what resist brute-force and dictionary attacks.

  • ✓

    Is unique and not used on other accounts

    Why this is correct

    Reusing a password across accounts lets one breach compromise many systems, so uniqueness confines credential-stuffing damage to a single service. This satisfies the characteristic that a strong password must not be shared between accounts, preventing lateral compromise.

  • ✗

    Is reused across multiple accounts

    Why it's wrong here

    Reusing a password across accounts means one breach compromises every linked service through credential stuffing. Strong passwords are unique per account. Reuse would only be defensible where a password manager generates and stores distinct credentials, making memorisation unnecessary; the stem asks about characteristics of the password itself, not storage.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

7 more ways this is tested on FC0-U71

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following is the best practice for creating a strong password?

easy
  • A.Using your pet's name
  • B.Using the same password for multiple accounts
  • C.Using a sequence of 8 characters with letters only
  • ✓ D.Using a 14-character phrase with numbers and symbols

Why D: A strong password is at least 12 characters with a mix of uppercase, lowercase, numbers, and symbols.

Variation 2. Which TWO of the following are characteristics of a strong password? (Select TWO.)

easy
  • ✓ A.Includes uppercase letters, numbers, and symbols
  • B.Uses a common dictionary word
  • ✓ C.At least 12 characters long
  • D.Based on your birth date
  • E.Contains only lowercase letters

Why A: Option A is correct because a strong password should combine uppercase letters, numbers, and symbols to increase its character-set complexity, making brute-force and dictionary attacks far less effective. Option C is correct because a minimum length of at least 12 characters significantly increases the number of possible combinations, which is a key factor in resisting cracking attempts. Options B, D, and E are not correct: a common dictionary word (B) is easily guessed via dictionary attacks, a birth date (D) is predictable personal information, and using only lowercase letters (E) severely limits the character set and thus the password's strength.

Variation 3. Which of the following is a characteristic of a strong password?

easy
  • ✓ A.A password that is at least 12 characters long with a mix of character types
  • B.A short password with only letters
  • C.A password that is easy to remember, like a pet's name
  • D.A password that is the same across multiple accounts

Why A: A strong password should be at least 12 characters, include uppercase, lowercase, numbers, and symbols, and should not be reused or shared.

Variation 4. Which of the following is the strongest password?

easy
  • A.12345678
  • B.P@ssw0rd
  • ✓ C.MyD0g!sF1d0
  • D.password

Why C: MyD0g!sF1d0 is the strongest because it is the longest option (11 characters) and combines uppercase, lowercase, digits, and special characters in a non-dictionary phrase. Length is the primary driver of password strength, and this password avoids common words or predictable substitutions like 'P@ssw0rd'. It would take significantly longer to crack via brute force or dictionary attacks than the other options.

Variation 5. Which of the following is a characteristic of a strong password?

easy
  • ✓ A.Contains a combination of uppercase, lowercase, numbers, and symbols
  • B.Is exactly 8 characters long
  • C.Uses only lowercase letters
  • D.Is the same as the username

Why A: A strong password uses a mix of character types — uppercase, lowercase, numbers, and symbols — to increase entropy and resist brute-force and dictionary attacks. This complexity requirement is a widely accepted characteristic of strong passwords. Length also matters, but among the options, the combination of character classes is the defining characteristic.

Variation 6. Which of the following is a best practice for creating a strong password?

easy
  • ✓ A.Using a long passphrase that includes symbols and numbers
  • B.Using a password with 8 characters including letters and numbers
  • C.Reusing the same password across multiple sites
  • D.Using your pet's name as a password

Why A: A long passphrase that includes symbols and numbers is considered a best practice because it increases both length and complexity, making it significantly harder for attackers to crack using brute-force or dictionary attacks. Length is the most critical factor in password strength, and adding symbols and numbers further expands the search space. This approach aligns with guidance from NIST and other security organizations, which recommend passphrases over short, complex passwords.

Variation 7. Which of the following is the best practice for creating strong passwords?

medium
  • A.Use your birthday and pet's name
  • B.Use a common phrase with numbers replacing letters
  • ✓ C.Use a random combination of uppercase, lowercase, numbers, and symbols of at least 12 characters
  • D.Use the same password for all accounts but change it monthly

Why C: Strong passwords should be long (at least 12 characters, ideally 16+), random, and use a mix of uppercase, lowercase, numbers, and symbols to maximize entropy and resist brute-force and dictionary attacks. Option C reflects this best practice and aligns with NIST SP 800-63B guidance on length and complexity. Randomness is key — predictable patterns like birthdays or leetspeak phrases are easily cracked.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.