ISC2 CC Access Controls Concepts Practice Question
According to NIST SP 800-63, which password policy is most recommended?
⚠ Common exam trap
The trap is that candidates default to legacy advice—complexity and 30-day rotation—when NIST has explicitly moved away from both in favor of length and breach-list screening.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce a minimum length of 8 characters and check against breached password lists
NIST SP 800-63B recommends a minimum password length of 8 characters (with 15+ encouraged for memorized secrets) and screening new passwords against lists of commonly used and breached passwords. This approach prioritizes length and blocklist checks over forced complexity and rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow short passwords but require numbers and symbols
Why it's wrong here
Short passwords with numbers and symbols remain brute-forceable; NIST SP 800-63 favours longer memorised secrets, ideally passphrases, over composition on short strings. Composition rules are tempting because they appear to raise entropy, and would suit systems enforcing minimum complexity, but length dominates.
- ✗
Use complex passwords with special characters and minimal length
Why it's wrong here
NIST SP 800-63 recommends length over composition, advising against mandatory special-character rules; such complexity encourages predictable substitutions and reuse. It is tempting because complexity rules are traditional policy, and would fit contexts demanding composition, but they reduce memorability without adding real entropy.
- ✓
Enforce a minimum length of 8 characters and check against breached password lists
Why this is correct
NIST SP 800-63B advises against composition and rotation rules, favouring length and blocklist screening. An eight-character minimum combined with checking against breached password lists directly satisfies that guidance, blocking compromised credentials without imposing complexity or expiry requirements.
- ✗
Require frequent password changes every 30 days
Why it's wrong here
NIST SP 800-63 advises against forced periodic rotation, since frequent changes push users toward incremental, predictable variants. Rotation is tempting as a breach-containment measure, and would be correct after a confirmed credential compromise, but routine 30-day expiry weakens rather than strengthens passwords.
Go deeper
Related to this question
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Password policy
A set of rules designed to enhance computer security by encouraging users to create strong, secure passwords and store them properly.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.