Courseiva
Security →easyMultiple Select

FC0-U71 Security Practice Question

Which TWO of the following are best practices for password security?

⚠ Common exam trap

FC0-U71 often tests the misconception that complex-looking but reused passwords are secure — candidates overlook that uniqueness and MFA matter more than raw complexity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enabling multi-factor authentication whenever possible

Option A is correct because enabling multi-factor authentication (MFA) adds a second verification factor (something you have, such as a TOTP code or hardware token, or something you are, such as a fingerprint) on top of the password, so a stolen or guessed password alone is no longer sufficient to compromise the account. Option E is correct because a password manager generates high-entropy, unique passwords for each account and stores them encrypted (typically with AES-256) behind a single strong master passphrase, which eliminates password reuse and makes credential stuffing attacks ineffective. The remaining options are poor practices: B uses trivially guessable patterns that appear at the top of every breach wordlist, C enables credential stuffing and lateral movement because one breach exposes all accounts, and D destroys individual accountability and non-repudiation while widening the attack surface to every person who knows the shared secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enabling multi-factor authentication whenever possible

    Why this is correct

    Multi-factor authentication demands a second, independent factor beyond the password, so a stolen or guessed credential alone cannot grant access. This directly satisfies the password-security best-practice requirement by neutralising credential theft, replay and brute-force success.

  • ✗

    Using simple patterns like '123456' or 'password'

    Why it's wrong here

    '123456' and 'password' appear in every attacker wordlist and are cracked instantly by dictionary or brute-force attacks, so they provide no resistance to guessing. Such patterns are what complexity and length requirements exist to block; they would only be acceptable where no authentication is needed at all.

  • ✗

    Using the same password for multiple accounts

    Why it's wrong here

    Reusing one password means a single breach of any one site exposes every other account through credential-stuffing attacks. Unique credentials per account contain the blast radius of a compromise; reuse is the exact behaviour password managers and breach-monitoring policies are designed to eliminate.

  • ✗

    Sharing passwords with coworkers for convenience

    Why it's wrong here

    Sharing passwords destroys accountability, since audit logs can no longer attribute actions to an individual, and it multiplies exposure each time a colleague leaves or is compromised. Shared credentials suit only anonymous service accounts; individual user authentication requires unique accounts with delegated permissions instead.

  • ✓

    Using a password manager to generate and store strong passwords

    Why this is correct

    A password manager generates high-entropy unique passwords per site and stores them encrypted, removing reuse and weak human-chosen patterns. This satisfies the password-security best practice by eliminating the memory burden that drives credential recycling across accounts.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on FC0-U71

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. What is the primary purpose of a password manager?

easy
  • ✓ A.To generate and store strong, unique passwords
  • B.To store passwords in the cloud
  • C.To share passwords with others
  • D.To bypass authentication

Why A: A password manager's core function is to create strong, unique passwords for each account and securely store them in an encrypted vault. This eliminates password reuse and weak passwords, which are major security risks. The manager uses a master password to encrypt the vault, so only the user can access the stored credentials. Thus, option A accurately captures the primary purpose.

Variation 2. What is the primary purpose of a password manager?

easy
  • A.To store passwords in the cloud for easy access
  • B.To encrypt all network traffic
  • C.To share passwords securely with team members
  • ✓ D.To generate and store strong, unique passwords

Why D: A password manager's core function is to create high-entropy, unique passwords for every account and store them in an encrypted vault, eliminating password reuse and weak credentials. It uses a master password and strong encryption (e.g., AES-256) to protect the vault, and can auto-fill credentials, reducing human error. While some managers offer cloud sync or sharing, those are secondary features, not the primary purpose.

Variation 3. Which THREE of the following are best practices for password security?

medium
  • A.Sharing passwords with trusted coworkers when necessary
  • ✓ B.Enabling two-factor authentication where possible
  • ✓ C.Using a password manager to generate and store passwords
  • D.Reusing the same password across multiple sites
  • ✓ E.Using a password with at least 12 characters including uppercase, lowercase, numbers, and symbols

Why B: Option B is correct because enabling two-factor authentication (2FA) adds a second verification factor (e.g., TOTP, hardware token, or push notification) beyond the password, so a stolen or guessed password alone is insufficient to compromise the account. Option C is correct because a password manager generates high-entropy, unique credentials for each site and stores them encrypted (typically under AES-256 with a master passphrase), eliminating weak or reused passwords and reducing the risk of credential-stuffing attacks. Option E is correct because length and character diversity increase the search space, making brute-force and dictionary attacks computationally impractical; 12+ characters mixing uppercase, lowercase, digits, and symbols aligns with NIST and common policy guidance for strong passwords. Option A is wrong because sharing passwords destroys individual accountability and non-repudiation, and violates least-privilege and audit principles; use delegated accounts or role-based access instead. Option D is wrong because reusing one password across sites means a single breach exposes all accounts via credential stuffing, so every account should have a unique password.

Variation 4. What is the primary purpose of a password manager?

easy
  • ✓ A.To store passwords in an encrypted vault and generate complex passwords
  • B.To share passwords with other users securely
  • C.To automatically log in to websites without typing a password
  • D.To recover forgotten passwords quickly

Why A: A password manager's core function is to store credentials in an encrypted vault protected by a master password, and to generate strong, unique passwords for each site. This eliminates password reuse and weak passwords, which are the leading causes of credential-based breaches.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.