Courseiva
Access Controls Concepts →hardMultiple Select

ISC2 CC Access Controls Concepts Practice Question

According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)

⚠ Common exam trap

The CC exam often tests the outdated belief that complex passwords and frequent changes are recommended, while NIST now advises against them in favor of length and breach checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow users to paste passwords to facilitate password manager use

Option A is correct because NIST SP 800-63B explicitly recommends permitting "paste" functionality in password fields so that users can employ password managers, which generate and store strong, unique credentials. Option B is correct because the guideline requires verifiers to compare prospective passwords against lists of commonly used, expected, or compromised passwords (e.g., breach corpora) and reject matches. Option E is correct because NIST sets a minimum password length of 8 characters for user-chosen secrets, while encouraging longer passphrases (up to at least 64 characters). Option C is not recommended because NIST advises against composition rules mandating mixed uppercase, lowercase, digits, and symbols, since they push users toward predictable patterns. Option D is not recommended because NIST discourages forced periodic rotation (e.g., every 30 days) absent evidence of compromise, as it weakens password quality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Allow users to paste passwords to facilitate password manager use

    Why this is correct

    Allowing paste supports password managers, which NIST SP 800-63B explicitly endorses to reduce reuse and enable longer, higher-entropy secrets. Blocking paste forces weaker, memorable passwords and encourages poor workarounds. This satisfies the stem's recommendation for verifier practices that accommodate credential managers rather than impede them.

  • ✓

    Check passwords against known breached password lists

    Why this is correct

    Checking candidate passwords against breached-password corpora directly implements NIST SP 800-63B's verifier requirement to block compromised secrets at enrolment and reset. This satisfies the stem's constraint by detecting credentials already exposed in prior breaches, rather than relying on composition rules or expiry, which the guidance explicitly discourages.

  • ✗

    Require complex combinations of uppercase, lowercase, numbers, and symbols

    Why it's wrong here

    NIST SP 800-63 advises against composition rules, since they push users toward predictable patterns and weaker memorability without real entropy gains. It is tempting because complexity feels like stronger security, but composition rules would be appropriate only where a legacy standard explicitly mandates them.

  • ✗

    Require frequent password changes every 30 days

    Why it's wrong here

    NIST SP 800-63 advises against forced periodic rotation, since it drives predictable incremental variants and weaker memorised passwords. Frequent expiry is tempting because legacy compliance regimes mandated 30- or 90-day rotation, and it would be defensible only where a credential is suspected compromised and immediate revocation is impossible.

  • ✓

    Require a minimum length of 8 characters for most accounts

    Why this is correct

    NIST SP 800-63 favours length over composition, but its memorised-secret guidance sets a minimum of 8 characters when a password is chosen by the user, satisfying the stem's requirement for a recommended practice. Longer minimums (often 15) apply to single-factor passwords, so 8 aligns with the lower bound for most accounts.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.