mediumMultiple Select
FC0-U71 Practice Question: Which TWO of the following are best practices for…
Which TWO of the following are best practices for creating strong passwords?
⚠ Common exam trap
Many candidates think 'easily remembered' passwords are acceptable for convenience, but CompTIA emphasizes that security must override memorability, and personal information is a common target for attackers using OSINT (Open Source Intelligence).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Avoid using dictionary words or common phrases
Option B is correct because avoiding dictionary words and common phrases defends against dictionary and brute-force attacks, since attackers routinely test known words, leaked password lists, and predictable phrases first. Option D is correct because including a mix of uppercase, lowercase, numbers, and symbols increases the search space (entropy) an attacker must exhaust, making the password significantly harder to crack. Option A is incorrect because 'password123' is a well-known, commonly breached pattern that appears in every attacker wordlist. Option C is incorrect because personal information such as birth dates is easily discoverable and often guessable through social engineering or OSINT. Option E is incorrect because writing a password on a sticky note attached to the monitor exposes it to anyone who can physically see the workstation, defeating the purpose of the credential.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a common pattern like 'password123'
Why it's wrong here
'password123' appears in every credential-stuffing wordlist, so attackers crack it instantly. It tempts because it meets length and complexity rules superficially, and it would pass a naive policy checker that only counts characters without screening breached-password lists.
- ✓
Avoid using dictionary words or common phrases
Why this is correct
Dictionary words and common phrases are vulnerable to dictionary and brute-force attacks because attackers test known wordlists first. Excluding them removes predictable patterns, forcing attackers into vastly larger search spaces and making the password resistant to automated guessing.
- ✗
Use easily remembered personal information like birth dates
Why it's wrong here
Birth dates and similar personal details are guessable from social media and public records, so they weaken entropy. It tempts because such data is memorable without writing it down, and it would suit a low-risk account where memorability outweighs resistance to targeted guessing.
- ✓
Include a mix of uppercase, lowercase, numbers, and symbols
Why this is correct
Mixing uppercase, lowercase, digits and symbols expands the search space an attacker must exhaust, directly satisfying the stem's requirement for strong password creation. Because brute-force and dictionary attacks rely on predictable character sets, this complexity makes each guess costlier, raising cracking time substantially.
- ✗
Write the password on a sticky note and attach it to the monitor
Why it's wrong here
Writing a password on a sticky note exposes it to anyone passing the monitor, defeating confidentiality. It tempts as a memory aid when many complex passwords must be recalled, and would be acceptable only inside a physically secured safe or password manager vault.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.