easyMultiple Select
Secure Password Policy Best Practices
Which TWO of the following are best practices for creating and managing passwords?
⚠ Common exam trap
The trap here is that 'change passwords every 90 days' sounds like a security best practice from legacy training, but modern guidance (NIST) discourages forced rotation without evidence of compromise, so candidates who pick B are applying outdated advice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable multi-factor authentication where available
Option C is correct because enabling multi-factor authentication (MFA) adds a second verification factor (such as a TOTP code, push approval, or hardware security key) beyond the password, so a stolen or guessed password alone is insufficient to compromise the account. Option D is correct because using a unique password for each online account prevents credential-stuffing and password-spraying attacks from spreading: a breach at one site cannot be leveraged to access other accounts. The remaining options are poor practices: sharing passwords (A) destroys individual accountability and widens the attack surface, reusing passwords every 90 days (B) still allows one breach to compromise many accounts and ignores that forced periodic rotation without cause weakens security, and writing passwords on a sticky note near the computer (E) exposes credentials to anyone with physical or visual access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share passwords with colleagues in the same department to improve collaboration
Why it's wrong here
Sharing passwords destroys individual accountability, since audit logs can no longer attribute actions to one person, and it widens exposure with every colleague told. It is tempting because shared departmental credentials appear to simplify collaboration, but that is precisely the scenario where unique named accounts are required.
- ✗
Reuse passwords every 90 days
Why it's wrong here
Reusing passwords every 90 days means one credential compromise unlocks every account sharing it, and rotation does not undo that exposure. It is tempting because scheduled expiry limits how long a leaked password stays valid, which is why periodic rotation appears in older policy templates.
- ✓
Enable multi-factor authentication where available
Why this is correct
Multi-factor authentication adds a second, independent credential factor beyond the password, so a stolen or guessed password alone cannot grant access. This directly satisfies the best-practise requirement by mitigating credential compromise, the primary risk to password-based accounts.
- ✓
Use a unique password for each online account
Why this is correct
Reusing a password means one breach exposes every account sharing it, a technique attackers exploit through credential stuffing. Assigning a unique password per account confines any single compromise to that service, directly satisfying the best-practise requirement for limiting breach blast radius.
- ✗
Write down passwords on a sticky note and keep it near the computer
Why it's wrong here
A sticky note beside the computer exposes the password to anyone physically present, including cleaners and visitors, defeating confidentiality entirely. It is tempting because writing credentials down avoids lockouts from forgotten complex passwords, which is why offline password managers exist for that need.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.