SSCP Access Controls Practice Question
A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?
⚠ Common exam trap
SSCP often tests the trade-off between length, complexity, lockout, and history, tempting candidates to pick complexity-heavy but short passwords over longer ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Minimum 12 characters, complexity required, lockout after 5 attempts, history of 10
The strongest brute-force protection combines a long minimum length (12 characters), complexity requirements, a tight lockout threshold (5 attempts), and a deep password history (10) to prevent reuse. Length exponentially increases the search space, complexity widens the character set, lockout throttles online guessing, and history blocks cycling back to old passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Minimum 10 characters, no complexity, lockout after 3 attempts, history of 1
Why it's wrong here
Ten characters without complexity and a history of one weakens resistance; length alone does not offset predictable single-character-set passwords, and history of one permits immediate reuse. It is tempting because lockout after three attempts is strong, and would suit environments prioritising lockout over password diversity.
- ✗
Minimum 6 characters, complexity required, lockout after 10 attempts, history of 5
Why it's wrong here
A six-character minimum is trivially brute-forced regardless of complexity or lockout, since the search space stays tiny. Length is the dominant factor against brute force. Complexity and lockout settings are worthwhile hardening, but they cannot compensate for a short minimum, so this combination fails the compliance requirement.
- ✗
Minimum 8 characters, no complexity, no lockout, password history of 3
Why it's wrong here
Eight characters with no complexity, no lockout and history of three permits unlimited rapid guesses and weak passwords, so brute-force resistance is minimal. It is tempting as a usability-focused baseline, and would suit environments where lockout risks outweigh guessing threats, but compliance hardening requires length, complexity, lockout and longer history.
- ✓
Minimum 12 characters, complexity required, lockout after 5 attempts, history of 10
Why this is correct
Twelve-character minimum length with complexity raises brute-force search space, lockout after five attempts throttles online guessing, and history of ten blocks reuse of previously compromised passwords. Together these settings address brute-force and credential-reuse vectors more strongly than any shorter or lockout-free combination.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.