SY0-701 exam dumps

SY0-701 practice question 366 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 366

Single answerPassword concepts: Length , Complexity , Reuse , Expiration , Age

A security administrator is revising the company password policy after several user accounts were compromised through credential stuffing. The current policy requires 8-character passwords with upper/lowercase, numbers, and symbols, forces password changes every 30 days, and prevents reuse of the last 2 passwords. Users frequently choose minor variations such as Winter2024!, Winter2024@, and Winter2024#. Which change would BEST reduce the risk of future compromise while improving usability?

  1. A

    Increase the minimum password length to 14 characters, allow passphrases, block common and previously breached passwords, and require MFA while reducing frequent forced password changes unless compromise is suspected

  2. B

    Keep the 8-character complexity requirement, shorten expiration to every 14 days, and increase password history to remember the last 3 passwords

  3. C

    Require 6-digit PINs that rotate every 7 days because shorter secrets are easier for users to remember correctly

  4. D

    Maintain the current complexity rules but require users to append a different special character each month to avoid password reuse

Show answer and explanation

Correct answer: A

Explanation

The best answer is to strengthen password policy using modern, evidence-based practices. Current best practices, including NIST SP 800-63B Digital Identity Guidelines, favor longer passwords and passphrases over excessive composition rules, recommend checking proposed passwords against blocklists of commonly used or breached passwords, and discourage mandatory periodic password changes unless there is evidence of compromise. In this scenario, the organization's 30-day expiration policy and minimal password history are driving predictable reuse patterns and small modifications, which are ineffective against credential stuffing. Increasing minimum length, allowing memorable passphrases, and preventing use of compromised passwords directly address password length, complexity, reuse, expiration, and password age in a practical way. Adding MFA further mitigates the risk that stolen passwords alone can be used to access accounts.

  • A. Correct.

    Correct. This aligns with modern password guidance such as NIST SP 800-63B, which emphasizes longer passwords or passphrases, screening against commonly used and compromised passwords, and avoiding unnecessary periodic password resets unless there is evidence of compromise. Longer passwords generally provide more resistance to guessing than short, highly complex passwords, and MFA significantly reduces the impact of stolen credentials in credential-stuffing attacks.

  • B. Incorrect.

    Incorrect. More frequent expiration often leads users to make predictable, low-value changes, such as incrementing numbers or changing a symbol, which does little to stop credential stuffing. Keeping short 8-character passwords also provides less resilience than moving to longer passphrases. Increasing password history from 2 to 3 is only a minor improvement and does not address the main problem.

  • C. Incorrect.

    Incorrect. Replacing passwords with 6-digit PINs for general account authentication would substantially weaken security because PINs have a much smaller keyspace and are easier to brute-force. Frequent rotation every 7 days would also create a high user burden and likely encourage insecure workarounds.

  • D. Incorrect.

    Incorrect. Requiring users to append a different special character is a common but weak practice. It encourages predictable password evolution patterns, which attackers can anticipate. This approach preserves the weaknesses of short passwords and frequent forced changes rather than adopting stronger length-based controls and password screening.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam