SY0-701 exam dumps

SY0-701 practice question 364 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 364

Single answerPassword best practices

A security administrator is updating the company’s password policy after several help desk tickets revealed that employees frequently forget complex passwords and write them on sticky notes. The company wants to reduce password reuse and improve security without significantly increasing user frustration. Which of the following is the BEST recommendation to include in the new policy?

  1. A

    Require users to create short passwords with frequent mandatory changes every 30 days

  2. B

    Implement passphrases with a longer minimum length and screen new passwords against a banned password list

  3. C

    Allow users to keep the same password indefinitely as long as it contains uppercase, lowercase, numbers, and symbols

  4. D

    Require IT to assign random passwords to all users and prohibit self-service password changes

Show answer and explanation

Correct answer: B

Explanation

The best answer is to implement longer passphrases and check new passwords against a banned password list. Current best practices emphasize password length over arbitrary complexity and recommend blocking common, weak, or previously breached passwords. NIST SP 800-63B specifically recommends allowing longer passwords, comparing proposed passwords against lists of commonly used or compromised values, and avoiding unnecessary periodic password changes unless there is evidence of compromise. In a real-world environment, this approach improves both security and usability, reducing the likelihood that users will reuse passwords or write them down.

  • A. Incorrect.

    This is incorrect. Short passwords are easier to crack, even if they are changed frequently. Modern guidance has moved away from forcing frequent password changes unless there is evidence of compromise, because it often leads users to choose weaker, more predictable passwords or write them down.

  • B. Correct.

    This is correct. Longer passphrases are generally easier for users to remember and harder for attackers to crack than short complex passwords. Screening against a banned password list helps prevent the use of common, breached, or easily guessed passwords. This aligns with modern password best practices such as NIST SP 800-63B guidance.

  • C. Incorrect.

    This is incorrect. Complexity requirements alone do not make passwords strong enough, especially if users choose predictable patterns such as replacing letters with numbers. Allowing the same password indefinitely without checking for compromise, weak choices, or reuse does not adequately reduce risk.

  • D. Incorrect.

    This is incorrect. Randomly assigned passwords can be strong, but prohibiting self-service password changes increases administrative burden and user frustration. It also does not address usability concerns that often cause insecure behavior such as writing passwords down. Better policy design should balance security and usability.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam