ISC2 CC Access Controls Concepts Practice Question
An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?
⚠ Common exam trap
CC often tests whether candidates still hold the legacy belief that complexity and frequent rotation are the gold standard, when current NIST guidance explicitly reverses that in favor of length and no forced expiration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Length over complexity and no periodic changes
Current NIST SP 800-63B guidance recommends favoring password length over complexity and eliminating forced periodic rotation, because long passphrases resist brute-force and dictionary attacks better than short complex strings, and frequent changes lead users to predictable patterns (e.g., Password1!, Password2!). A 15-character minimum with no complexity rules and no forced expiration aligns with this modern best practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Passwords should be exactly 8 characters with at least one special character
Why it's wrong here
Eight characters with complexity and forced rotation reflects outdated guidance; NIST now recommends length over composition and no arbitrary expiry. It is tempting because complexity feels stronger, but the stem's 15-character, no-complexity, no-rotation policy is the current best practice, not this.
- ✗
Passwords should be changed every 30 days
Why it's wrong here
Thirty-day rotation is now discouraged; frequent changes drive predictable increments and weaker passwords. It is tempting because periodic expiry was long taught as hygiene, but NIST recommends against arbitrary expiration when length and breach monitoring are used, matching the stem's 15-character no-rotation policy.
- ✗
Complexity requirements are more important than length
Why it's wrong here
Length and complexity are complementary controls, not competing ones; NIST guidance favours length because it expands the search space far more than forced character-class mixing. Complexity rules do raise entropy per character, so they matter where maximum-length caps or legacy systems constrain password size, but they are not the priority the stem's 15-character policy reflects.
- ✓
Length over complexity and no periodic changes
Why this is correct
NIST guidance favours longer passphrases over forced complexity and drops mandatory periodic rotation, since length resists cracking while frequent changes push users toward predictable patterns. A 15-character minimum with no complexity rules and no expiry matches this modern approach.
Go deeper
Related to this question
Key term
Password policy
A set of rules designed to enhance computer security by encouraging users to create strong, secure passwords and store them properly.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.