FC0-U71 Security Practice Question
Which TWO of the following are best practices for password security?
⚠ Common exam trap
FC0-U71 often tests the misconception that complex-looking but reused passwords are secure — candidates overlook that uniqueness and MFA matter more than raw complexity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enabling multi-factor authentication whenever possible
Option A is correct because enabling multi-factor authentication (MFA) adds a second verification factor (something you have, such as a TOTP code or hardware token, or something you are, such as a fingerprint) on top of the password, so a stolen or guessed password alone is no longer sufficient to compromise the account. Option E is correct because a password manager generates high-entropy, unique passwords for each account and stores them encrypted (typically with AES-256) behind a single strong master passphrase, which eliminates password reuse and makes credential stuffing attacks ineffective. The remaining options are poor practices: B uses trivially guessable patterns that appear at the top of every breach wordlist, C enables credential stuffing and lateral movement because one breach exposes all accounts, and D destroys individual accountability and non-repudiation while widening the attack surface to every person who knows the shared secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enabling multi-factor authentication whenever possible
Why this is correct
Multi-factor authentication demands a second, independent factor beyond the password, so a stolen or guessed credential alone cannot grant access. This directly satisfies the password-security best-practice requirement by neutralising credential theft, replay and brute-force success.
- ✗
Using simple patterns like '123456' or 'password'
Why it's wrong here
'123456' and 'password' appear in every attacker wordlist and are cracked instantly by dictionary or brute-force attacks, so they provide no resistance to guessing. Such patterns are what complexity and length requirements exist to block; they would only be acceptable where no authentication is needed at all.
- ✗
Using the same password for multiple accounts
Why it's wrong here
Reusing one password means a single breach of any one site exposes every other account through credential-stuffing attacks. Unique credentials per account contain the blast radius of a compromise; reuse is the exact behaviour password managers and breach-monitoring policies are designed to eliminate.
- ✗
Sharing passwords with coworkers for convenience
Why it's wrong here
Sharing passwords destroys accountability, since audit logs can no longer attribute actions to an individual, and it multiplies exposure each time a colleague leaves or is compromised. Shared credentials suit only anonymous service accounts; individual user authentication requires unique accounts with delegated permissions instead.
- ✓
Using a password manager to generate and store strong passwords
Why this is correct
A password manager generates high-entropy unique passwords per site and stores them encrypted, removing reuse and weak human-chosen patterns. This satisfies the password-security best practice by eliminating the memory burden that drives credential recycling across accounts.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on FC0-U71
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. What is the primary purpose of a password manager?
easy- ✓ A.To generate and store strong, unique passwords
- B.To store passwords in the cloud
- C.To share passwords with others
- D.To bypass authentication
Why A: A password manager's core function is to create strong, unique passwords for each account and securely store them in an encrypted vault. This eliminates password reuse and weak passwords, which are major security risks. The manager uses a master password to encrypt the vault, so only the user can access the stored credentials. Thus, option A accurately captures the primary purpose.
Variation 2. What is the primary purpose of a password manager?
easy- A.To store passwords in the cloud for easy access
- B.To encrypt all network traffic
- C.To share passwords securely with team members
- ✓ D.To generate and store strong, unique passwords
Why D: A password manager's core function is to create high-entropy, unique passwords for every account and store them in an encrypted vault, eliminating password reuse and weak credentials. It uses a master password and strong encryption (e.g., AES-256) to protect the vault, and can auto-fill credentials, reducing human error. While some managers offer cloud sync or sharing, those are secondary features, not the primary purpose.
Variation 3. Which THREE of the following are best practices for password security?
medium- A.Sharing passwords with trusted coworkers when necessary
- ✓ B.Enabling two-factor authentication where possible
- ✓ C.Using a password manager to generate and store passwords
- D.Reusing the same password across multiple sites
- ✓ E.Using a password with at least 12 characters including uppercase, lowercase, numbers, and symbols
Why B: Option B is correct because enabling two-factor authentication (2FA) adds a second verification factor (e.g., TOTP, hardware token, or push notification) beyond the password, so a stolen or guessed password alone is insufficient to compromise the account. Option C is correct because a password manager generates high-entropy, unique credentials for each site and stores them encrypted (typically under AES-256 with a master passphrase), eliminating weak or reused passwords and reducing the risk of credential-stuffing attacks. Option E is correct because length and character diversity increase the search space, making brute-force and dictionary attacks computationally impractical; 12+ characters mixing uppercase, lowercase, digits, and symbols aligns with NIST and common policy guidance for strong passwords. Option A is wrong because sharing passwords destroys individual accountability and non-repudiation, and violates least-privilege and audit principles; use delegated accounts or role-based access instead. Option D is wrong because reusing one password across sites means a single breach exposes all accounts via credential stuffing, so every account should have a unique password.
Variation 4. What is the primary purpose of a password manager?
easy- ✓ A.To store passwords in an encrypted vault and generate complex passwords
- B.To share passwords with other users securely
- C.To automatically log in to websites without typing a password
- D.To recover forgotten passwords quickly
Why A: A password manager's core function is to store credentials in an encrypted vault protected by a master password, and to generate strong, unique passwords for each site. This eliminates password reuse and weak passwords, which are the leading causes of credential-based breaches.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.