nerdexam
CompTIA

PT0-001 · Question #59

Which of the following excerpts would come from a corporate policy?

The correct answer is D. The corporate systems must store passwords using the MD5 hashing algorithm. A corporate policy issues binding directives that govern how organizational systems must operate, and only option D frames a mandate at the system level in policy form.

Engagement management

Question

Which of the following excerpts would come from a corporate policy?

Options

  • AEmployee passwords must contain a minimum of eight characters, with one being alphanumeric.
  • BThe help desk can be reached at 800-passwd1 to perform password resets.
  • CEmployees must use strong passwords for accessing corporate assets.
  • DThe corporate systems must store passwords using the MD5 hashing algorithm.

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    2% (1)
  • D
    91% (51)

Why each option

A corporate policy issues binding directives that govern how organizational systems must operate, and only option D frames a mandate at the system level in policy form.

AEmployee passwords must contain a minimum of eight characters, with one being alphanumeric.

Specifying a minimum password length of eight characters with one alphanumeric character is a technical password standard - it defines specific, measurable requirements that belong in a standards document rather than a high-level policy.

BThe help desk can be reached at 800-passwd1 to perform password resets.

Providing a help desk contact number for password resets is procedural or reference documentation, not a binding policy statement that governs organizational system behavior.

CEmployees must use strong passwords for accessing corporate assets.

Directing employees to use 'strong passwords' is characteristic of a guideline, which offers general recommendations without mandating specific technical implementations, and therefore lacks the binding authority of a policy.

DThe corporate systems must store passwords using the MD5 hashing algorithm.Correct

Corporate policies establish binding organizational directives that govern system and operational behavior across the enterprise. Stating that corporate systems must store passwords using a specific algorithm (MD5) is a system-level mandate written in the authoritative tone of a policy document. While MD5 is cryptographically weak for password storage, as a structural excerpt it matches the format and authority level of a corporate policy rather than a guideline or procedural reference.

Concept tested: Distinguishing policy from standards, guidelines, and procedures

Source: https://csrc.nist.gov/glossary/term/policy

Topics

#security policy#governance#password policy#compliance

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice