Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A password policy requires passwords to be at…

A password policy requires passwords to be at least 12 characters, with uppercase, lowercase, digits, and special characters. Which of the following is an example of a password that meets the policy?

⚠ Common exam trap

The trap here is that candidates often overlook the exact length requirement and focus only on character variety, leading them to select options like C or D that contain all character types but are shorter than 12 characters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Password123!

(Password123!) meets the policy because it is 12 characters long and includes uppercase (P), lowercase (assword), digits (123), and a special character (!). The policy requires all four character types, and this password satisfies each requirement without any ambiguity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Abcdefghijkl

    Why it's wrong here

    The password "Abcdefghijkl" meets the minimum length requirement of 12 characters. However, it fails to meet typical modern password policy complexity requirements, as it consists solely of lowercase alphabetic characters. Without the inclusion of uppercase letters, digits, or special characters, its entropy is significantly reduced, making it highly susceptible to dictionary attacks and less secure against brute-force attempts.

  • Pa$$w0rd

    Why it's wrong here

    The password "Pa$$w0rd" is only 8 characters long, which directly violates the stated policy requiring passwords to be at least 12 characters. Despite incorporating a mix of character types, including uppercase, lowercase, digits, and special characters, its insufficient length significantly reduces its overall entropy and makes it much more vulnerable to rapid brute-force attacks, rendering it non-compliant.

  • MyP@ssw0rd1

    Why it's wrong here

    This password, "MyP@ssw0rd1," despite its commendable inclusion of uppercase, lowercase, digits, and a special character, totals only 11 characters. This specific length makes it non-compliant with the policy's explicit demand for passwords to be "at least 12 characters," thereby failing the fundamental length criterion and making it unacceptable under the specified security controls.

  • SecureP@ss1

    Why it's wrong here

    The password "SecureP@ss1" is precisely 11 characters long, which constitutes a direct violation of the stated policy requiring passwords to be "at least 12 characters." While it incorporates various character types, its failure to meet the minimum length requirement significantly compromises its overall strength and renders it unacceptable under the specified security controls, regardless of its perceived complexity.

  • Password123!

    Why this is correct

    The password "Password123!" successfully meets all implied and explicit requirements of a robust password policy. It is exactly 12 characters long, fulfilling the minimum length mandate. Furthermore, it incorporates a strong mix of character types: an uppercase letter ('P'), lowercase letters ('assword'), digits ('123'), and a special character ('!'), significantly enhancing its entropy and resistance against various cracking methods.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.