ISC2 CC Access Controls Concepts Practice Question
According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)
⚠ Common exam trap
The CC exam often tests the outdated belief that complex passwords and frequent changes are recommended, while NIST now advises against them in favor of length and breach checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow users to paste passwords to facilitate password manager use
Option A is correct because NIST SP 800-63B explicitly recommends permitting "paste" functionality in password fields so that users can employ password managers, which generate and store strong, unique credentials. Option B is correct because the guideline requires verifiers to compare prospective passwords against lists of commonly used, expected, or compromised passwords (e.g., breach corpora) and reject matches. Option E is correct because NIST sets a minimum password length of 8 characters for user-chosen secrets, while encouraging longer passphrases (up to at least 64 characters). Option C is not recommended because NIST advises against composition rules mandating mixed uppercase, lowercase, digits, and symbols, since they push users toward predictable patterns. Option D is not recommended because NIST discourages forced periodic rotation (e.g., every 30 days) absent evidence of compromise, as it weakens password quality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allow users to paste passwords to facilitate password manager use
Why this is correct
Allowing paste supports password managers, which NIST SP 800-63B explicitly endorses to reduce reuse and enable longer, higher-entropy secrets. Blocking paste forces weaker, memorable passwords and encourages poor workarounds. This satisfies the stem's recommendation for verifier practices that accommodate credential managers rather than impede them.
- ✓
Check passwords against known breached password lists
Why this is correct
Checking candidate passwords against breached-password corpora directly implements NIST SP 800-63B's verifier requirement to block compromised secrets at enrolment and reset. This satisfies the stem's constraint by detecting credentials already exposed in prior breaches, rather than relying on composition rules or expiry, which the guidance explicitly discourages.
- ✗
Require complex combinations of uppercase, lowercase, numbers, and symbols
Why it's wrong here
NIST SP 800-63 advises against composition rules, since they push users toward predictable patterns and weaker memorability without real entropy gains. It is tempting because complexity feels like stronger security, but composition rules would be appropriate only where a legacy standard explicitly mandates them.
- ✗
Require frequent password changes every 30 days
Why it's wrong here
NIST SP 800-63 advises against forced periodic rotation, since it drives predictable incremental variants and weaker memorised passwords. Frequent expiry is tempting because legacy compliance regimes mandated 30- or 90-day rotation, and it would be defensible only where a credential is suspected compromised and immediate revocation is impossible.
- ✓
Require a minimum length of 8 characters for most accounts
Why this is correct
NIST SP 800-63 favours length over composition, but its memorised-secret guidance sets a minimum of 8 characters when a password is chosen by the user, satisfying the stem's requirement for a recommended practice. Longer minimums (often 15) apply to single-factor passwords, so 8 aligns with the lower bound for most accounts.
Go deeper
Related to this question
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Guideline
A guideline is a recommended set of best practices or instructions that provide direction for implementing, managing, or governing IT processes, without being strictly mandatory or enforced like a policy.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.