Courseiva
mediumMultiple Select

SSCP Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for password management?

⚠ Common exam trap

SSCP often tests the misconception that password reuse or plaintext storage are acceptable for convenience, or that sharing passwords via email is secure, when these are clear violations of security best practices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement account lockout after a few failed attempts

Option A is correct because implementing account lockout after a few failed attempts mitigates brute-force and password-guessing attacks by temporarily disabling the account after a threshold of invalid logins, a core control in standards like NIST SP 800-53 and CIS Benchmarks. Option E is correct because enforcing password complexity requirements (e.g., minimum length, mixed character classes) increases the search space an attacker must cover, making dictionary and brute-force attacks less likely to succeed. Option B is incorrect because allowing reuse of the last 5 passwords undermines password history policies and lets compromised or previously breached credentials remain valid. Option C is incorrect because storing passwords in plaintext exposes them to any attacker or insider with file access; passwords should be salted and hashed with a strong algorithm such as bcrypt, scrypt, or Argon2. Option D is incorrect because sharing passwords via email transmits credentials in cleartext over untrusted channels and violates the principle of individual accountability; credentials should never be shared, and privileged access should use vaulting or PAM solutions instead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement account lockout after a few failed attempts

    Why this is correct

    Account lockout after a small number of failed attempts throttles online brute-force and password-guessing attacks, since further tries are refused for a set period. It satisfies the best-practice requirement by limiting an attacker's attempt rate against a known account.

  • ✗

    Allow reuse of the last 5 passwords

    Why it's wrong here

    Permitting reuse of the last five passwords lets a compromised credential be cycled back into service, undermining rotation. It is tempting because users forget new passwords, and it would be acceptable only where no rotation policy or breach exposure exists.

  • ✗

    Store passwords in plaintext for quick recovery

    Why it's wrong here

    Plaintext storage exposes every credential to anyone reading the file, defeating the purpose of hashing and salting. It is tempting because recovery feels convenient, and it would be acceptable only for non-sensitive throwaway values where disclosure causes no harm.

  • ✗

    Share passwords via email for convenience

    Why it's wrong here

    Email transmits credentials in cleartext across mail servers, where they persist in inboxes and logs. It is tempting because sharing is sometimes unavoidable, and it would be correct only through an encrypted, expiring secret-sharing channel rather than ordinary mail.

  • ✓

    Enforce password complexity requirements

    Why this is correct

    Complexity requirements force longer, mixed-character passwords that resist dictionary and brute-force cracking, raising the effective search space. Enforcing them at creation and change satisfies the best-practice constraint by preventing weak, easily guessed credentials across the estate.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.