100-140 Question 348
Select 3A user in your organization reports that their account was recently compromised. Upon investigation, you discover they reused the same password across multiple platforms and included personal information such as their birth year in the password. Which of the following are best practices to improve password security and prevent future compromises?
- A
Use unique passwords for each platform or service.
- B
Include personal information, such as birth dates, for easy recall.
- C
Create a password that is at least 12 characters long and includes a mix of uppercase letters, lowercase letters, numbers, and special characters.
- D
Store passwords in a secure, encrypted password manager.
- E
Share passwords only with trusted colleagues to ensure continuity of access.
Show answer and explanation
Correct answers: A, C, D
Explanation
Strong password practices, such as using unique, complex passwords and securely storing them in a password manager, significantly reduce the risk of account compromises. Avoiding personal information in passwords and refraining from sharing them with others further enhances security.
- A. Correct.
Using unique passwords for each platform ensures that if one password is compromised, other accounts remain secure.
- B. Incorrect.
Including personal information in a password makes it easier for attackers to guess, especially if the information is publicly available.
- C. Correct.
Creating long passwords with a mix of characters increases their complexity, making them harder to crack through brute force or dictionary attacks.
- D. Correct.
Using a secure, encrypted password manager helps users safely store and manage complex, unique passwords across platforms.
- E. Incorrect.
Sharing passwords, even with trusted colleagues, increases the risk of unauthorized access and should be avoided.