nerdexam
(ISC)2

SSCP · Question #153

Passwords can be required to change monthly, quarterly, or at other intervals:

The correct answer is B. depending on the criticality of the information needing protection and the password's. Option B is correct because password change intervals should be determined by two factors together: the criticality of the information being protected and the password's frequency of use. High-value systems with frequently used passwords warrant more aggressive rotation…

Submitted by lars.no· Apr 18, 2026Access Controls

Question

Passwords can be required to change monthly, quarterly, or at other intervals:

Options

  • Adepending on the criticality of the information needing protection
  • Bdepending on the criticality of the information needing protection and the password's
  • Cdepending on the password's frequency of use
  • Dnot depending on the criticality of the information needing protection but depending on the

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    91% (20)
  • C
    5% (1)

Explanation

Option B is correct because password change intervals should be determined by two factors together: the criticality of the information being protected and the password's frequency of use. High-value systems with frequently used passwords warrant more aggressive rotation schedules.

Why the distractors are wrong:

  • A is incomplete - criticality of information alone is only half the picture; how often a password is used also affects its exposure risk.
  • C is the mirror of A - frequency of use alone is insufficient; a rarely-used password protecting highly sensitive data still warrants frequent rotation.
  • D explicitly negates criticality, which contradicts established security policy - the sensitivity of protected data is always a core factor in setting password policies.

Memory tip: Think "C + F = Policy" - Criticality of data and Frequency of use together drive the rotation schedule. Any answer that drops either factor, or worse, excludes criticality, is wrong.

Topics

#Password Policies#Access Controls#Information Criticality#Security Best Practices

Community Discussion

No community discussion yet for this question.

Full SSCP Practice