ISC2 CC Access Controls Concepts Practice Question
Which THREE are recommended practices for password policies according to current guidelines?
⚠ Common exam trap
The trap here is that many candidates still believe traditional complexity and frequent expiration are best practices, but current guidelines (e.g., NIST) explicitly advise against them, favoring length and breach checks instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check passwords against lists of known breached passwords
Option A is correct because current NIST SP 800-63B guidance requires screening new passwords against lists of known compromised or breached passwords (such as those from Have I Been Pwned) and rejecting any that match. Option B is correct because NIST sets the minimum password length at 8 characters when a password is used as a single-factor authenticator. Option D is correct because NIST recommends permitting passwords up to at least 64 characters, allowing the use of long passphrases and password managers. Option C is not recommended because composition rules (mixing uppercase, numbers, and special characters) are now discouraged as they push users toward predictable patterns. Option E is not recommended because arbitrary periodic rotation (for example, every 30 days) is discouraged; changes should only be forced when there is evidence of compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check passwords against lists of known breached passwords
Why this is correct
Checking passwords against breached-password lists blocks credentials already exposed in known data breaches, directly satisfying the guideline to screen for compromised passwords. Microsoft Entra ID implements this natively through its banned-password list, which is populated from breach data and automatically rejects matching entries during password set or reset.
- ✓
Require passwords at least 8 characters long
Why this is correct
An eight-character minimum satisfies the length constraint while remaining usable, aligning with guidance that favours longer passphrases over frequent forced rotation. Microsoft Entra ID enforces a 14-character default for cloud accounts, so eight is the recognised floor rather than the target. This makes it a recommended baseline practice.
- ✗
Require at least one uppercase letter, one number, and one special character
Why it's wrong here
Current guidance (NIST SP 800-63B) advises against composition rules, since forced character classes produce predictable patterns and encourage weaker, reused passwords. It is tempting because complexity requirements appear to strengthen credentials, but length, blocklists and rate limiting are recommended instead.
- ✓
Allow passwords up to 64 characters
Why this is correct
Permitting passwords up to 64 characters satisfies the length constraint by accommodating passphrases and password-manager-generated secrets, which current guidance favours over forced complexity and expiry. Microsoft Entra ID supports a 256-character maximum, so a 64-character ceiling imposes no practical barrier while enabling stronger, unique credentials.
- ✗
Force password changes every 30 days
Why it's wrong here
Forcing changes every 30 days is discouraged because it drives predictable increments and reuse; current guidance favours screening against breached-password lists plus MFA. It is tempting as a containment measure, and would suit a legacy environment lacking breach monitoring or centralised identity controls.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.