nerdexam
CompTIA

CAS-005 · Question #120

A security administrator at a global organization wants to update password complexity rules for a system containing personally identifiable information. Which of the following would be the best…

The correct answer is A. NIST. NIST (National Institute of Standards and Technology): Provides comprehensive password guidelines (e.g., SP 800-63B) widely used for securing systems, including handling PII. GDPR (General Data Protection Regulation): Focuses on data privacy laws rather than technical password…

Submitted by renata2k· Mar 6, 2026Governance, Risk, and Compliance

Question

A security administrator at a global organization wants to update password complexity rules for a system containing personally identifiable information. Which of the following would be the best resource for this information?

Options

  • ANIST
  • BGDPR
  • CCMMI
  • DCOPPA

How the community answered

(44 responses)
  • A
    93% (41)
  • C
    2% (1)
  • D
    5% (2)

Explanation

NIST (National Institute of Standards and Technology): Provides comprehensive password guidelines (e.g., SP 800-63B) widely used for securing systems, including handling PII. GDPR (General Data Protection Regulation): Focuses on data privacy laws rather than technical password policies. CMMI (Capability Maturity Model Integration): Addresses process improvement, not password COPPA (Children's Online Privacy Protection Act): Focuses on child data privacy, not password

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice