Courseiva
Access Controls Concepts →mediumMultiple Select

ISC2 CC Access Controls Concepts Practice Question

Which THREE are recommended practices for password policies according to current guidelines?

⚠ Common exam trap

The trap here is that many candidates still believe traditional complexity and frequent expiration are best practices, but current guidelines (e.g., NIST) explicitly advise against them, favoring length and breach checks instead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check passwords against lists of known breached passwords

Option A is correct because current NIST SP 800-63B guidance requires screening new passwords against lists of known compromised or breached passwords (such as those from Have I Been Pwned) and rejecting any that match. Option B is correct because NIST sets the minimum password length at 8 characters when a password is used as a single-factor authenticator. Option D is correct because NIST recommends permitting passwords up to at least 64 characters, allowing the use of long passphrases and password managers. Option C is not recommended because composition rules (mixing uppercase, numbers, and special characters) are now discouraged as they push users toward predictable patterns. Option E is not recommended because arbitrary periodic rotation (for example, every 30 days) is discouraged; changes should only be forced when there is evidence of compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check passwords against lists of known breached passwords

    Why this is correct

    Checking passwords against breached-password lists blocks credentials already exposed in known data breaches, directly satisfying the guideline to screen for compromised passwords. Microsoft Entra ID implements this natively through its banned-password list, which is populated from breach data and automatically rejects matching entries during password set or reset.

  • ✓

    Require passwords at least 8 characters long

    Why this is correct

    An eight-character minimum satisfies the length constraint while remaining usable, aligning with guidance that favours longer passphrases over frequent forced rotation. Microsoft Entra ID enforces a 14-character default for cloud accounts, so eight is the recognised floor rather than the target. This makes it a recommended baseline practice.

  • ✗

    Require at least one uppercase letter, one number, and one special character

    Why it's wrong here

    Current guidance (NIST SP 800-63B) advises against composition rules, since forced character classes produce predictable patterns and encourage weaker, reused passwords. It is tempting because complexity requirements appear to strengthen credentials, but length, blocklists and rate limiting are recommended instead.

  • ✓

    Allow passwords up to 64 characters

    Why this is correct

    Permitting passwords up to 64 characters satisfies the length constraint by accommodating passphrases and password-manager-generated secrets, which current guidance favours over forced complexity and expiry. Microsoft Entra ID supports a 256-character maximum, so a 64-character ceiling imposes no practical barrier while enabling stronger, unique credentials.

  • ✗

    Force password changes every 30 days

    Why it's wrong here

    Forcing changes every 30 days is discouraged because it drives predictable increments and reuse; current guidance favours screening against breached-password lists plus MFA. It is tempting as a containment measure, and would suit a legacy environment lacking breach monitoring or centralised identity controls.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.