SSCP · Question #1136
A good password policy uses which of the following guidelines? (Choose all that apply)
The correct answer is C. Passwords should be audited on a regular basis D. Passwords should never be shared or written down. A good password policy involves regularly auditing passwords and strictly prohibiting their sharing or writing down to maintain robust security.
Question
A good password policy uses which of the following guidelines? (Choose all that apply)
Options
- APasswords should contain some form of your name oruserid
- BPasswords should always use words that can be found in a dictionary
- CPasswords should be audited on a regular basis
- DPasswords should never be shared or written down
How the community answered
(34 responses)- A3% (1)
- B12% (4)
- C85% (29)
Why each option
A good password policy involves regularly auditing passwords and strictly prohibiting their sharing or writing down to maintain robust security.
Including personal information like a name or user ID makes passwords highly predictable and vulnerable to guessing or social engineering attacks.
Using dictionary words makes passwords susceptible to dictionary attacks, where automated tools quickly test common words to gain unauthorized access.
Regularly auditing passwords helps identify weak, reused, or compromised credentials, ensuring compliance with security policies and validating the effectiveness of security controls.
Passwords should never be shared or written down to prevent unauthorized access and protect the confidentiality and integrity of user accounts from social engineering or physical theft.
Concept tested: Password policy best practices
Source: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/pin-policy-best-practices#password-policy-recommendations
Topics
Community Discussion
No community discussion yet for this question.