Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

According to NIST SP 800-63, which password policy is most recommended?

⚠ Common exam trap

The trap is that candidates default to legacy advice—complexity and 30-day rotation—when NIST has explicitly moved away from both in favor of length and breach-list screening.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce a minimum length of 8 characters and check against breached password lists

NIST SP 800-63B recommends a minimum password length of 8 characters (with 15+ encouraged for memorized secrets) and screening new passwords against lists of commonly used and breached passwords. This approach prioritizes length and blocklist checks over forced complexity and rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow short passwords but require numbers and symbols

    Why it's wrong here

    Short passwords with numbers and symbols remain brute-forceable; NIST SP 800-63 favours longer memorised secrets, ideally passphrases, over composition on short strings. Composition rules are tempting because they appear to raise entropy, and would suit systems enforcing minimum complexity, but length dominates.

  • ✗

    Use complex passwords with special characters and minimal length

    Why it's wrong here

    NIST SP 800-63 recommends length over composition, advising against mandatory special-character rules; such complexity encourages predictable substitutions and reuse. It is tempting because complexity rules are traditional policy, and would fit contexts demanding composition, but they reduce memorability without adding real entropy.

  • ✓

    Enforce a minimum length of 8 characters and check against breached password lists

    Why this is correct

    NIST SP 800-63B advises against composition and rotation rules, favouring length and blocklist screening. An eight-character minimum combined with checking against breached password lists directly satisfies that guidance, blocking compromised credentials without imposing complexity or expiry requirements.

  • ✗

    Require frequent password changes every 30 days

    Why it's wrong here

    NIST SP 800-63 advises against forced periodic rotation, since frequent changes push users toward incremental, predictable variants. Rotation is tempting as a breach-containment measure, and would be correct after a confirmed credential compromise, but routine 30-day expiry weakens rather than strengthens passwords.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.