nerdexam
GIAC

GSEC · Question #384

Which of the following is a valid password for a system with the default "Password must meet complexity requirements" setting enabled as part of the GPO Password policy requirements?

The correct answer is D. SaNS2006. Windows password complexity requires characters from at least 3 of 4 categories - uppercase, lowercase, digits, and special characters - and only 'SaNS2006' satisfies this requirement.

Access Control and Password Management

Question

Which of the following is a valid password for a system with the default "Password must meet complexity requirements" setting enabled as part of the GPO Password policy requirements?

Options

  • AThe Cat Chased its Tail AII Night
  • Bdisk ACCESS failed
  • CSETI@HOME
  • DSaNS2006

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    7% (2)
  • C
    4% (1)
  • D
    79% (22)

Why each option

Windows password complexity requires characters from at least 3 of 4 categories - uppercase, lowercase, digits, and special characters - and only 'SaNS2006' satisfies this requirement.

AThe Cat Chased its Tail AII Night

'The Cat Chased its Tail AII Night' contains only uppercase and lowercase letters - spaces are not counted as a special character category under Windows complexity requirements - satisfying only 2 of the required 3 categories.

Bdisk ACCESS failed

'disk ACCESS failed' contains only uppercase and lowercase letters, and spaces do not count as special characters under the Windows complexity policy, so it meets only 2 of the required 3 character categories.

CSETI@HOME

SETI@HOME contains only uppercase letters and a special character, satisfying only 2 of the required 3 character categories and therefore failing the complexity requirement.

DSaNS2006Correct

SaNS2006 contains uppercase letters (S, N, S), at least one lowercase letter (a), and digits (2006), satisfying 3 of the 4 character categories required by the Windows 'Password must meet complexity requirements' GPO policy. It also meets the default minimum length of 6 characters, making it the only valid password among the choices.

Concept tested: Windows GPO password complexity requirements categories

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/password-must-meet-complexity-requirements

Topics

#password complexity#GPO password policy#Windows authentication#complexity requirements

Community Discussion

No community discussion yet for this question.

Full GSEC Practice