Courseiva
Access Controls Concepts →hardMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?

⚠ Common exam trap

CC often tests whether candidates still hold the legacy belief that complexity and frequent rotation are the gold standard, when current NIST guidance explicitly reverses that in favor of length and no forced expiration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Length over complexity and no periodic changes

Current NIST SP 800-63B guidance recommends favoring password length over complexity and eliminating forced periodic rotation, because long passphrases resist brute-force and dictionary attacks better than short complex strings, and frequent changes lead users to predictable patterns (e.g., Password1!, Password2!). A 15-character minimum with no complexity rules and no forced expiration aligns with this modern best practice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Passwords should be exactly 8 characters with at least one special character

    Why it's wrong here

    Eight characters with complexity and forced rotation reflects outdated guidance; NIST now recommends length over composition and no arbitrary expiry. It is tempting because complexity feels stronger, but the stem's 15-character, no-complexity, no-rotation policy is the current best practice, not this.

  • ✗

    Passwords should be changed every 30 days

    Why it's wrong here

    Thirty-day rotation is now discouraged; frequent changes drive predictable increments and weaker passwords. It is tempting because periodic expiry was long taught as hygiene, but NIST recommends against arbitrary expiration when length and breach monitoring are used, matching the stem's 15-character no-rotation policy.

  • ✗

    Complexity requirements are more important than length

    Why it's wrong here

    Length and complexity are complementary controls, not competing ones; NIST guidance favours length because it expands the search space far more than forced character-class mixing. Complexity rules do raise entropy per character, so they matter where maximum-length caps or legacy systems constrain password size, but they are not the priority the stem's 15-character policy reflects.

  • ✓

    Length over complexity and no periodic changes

    Why this is correct

    NIST guidance favours longer passphrases over forced complexity and drops mandatory periodic rotation, since length resists cracking while frequent changes push users toward predictable patterns. A 15-character minimum with no complexity rules and no expiry matches this modern approach.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.