nerdexam
CompTIA

SY0-501 · Question #287

While reviewing the security controls in place for a web-based application, a security controls assessor notices that there are no password strength requirements in place. Because of this vulnerabilit

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #287. The question stem and answer options stay visible for context.

Submitted by kavita_s· Mar 4, 2026Security operations

Question

While reviewing the security controls in place for a web-based application, a security controls assessor notices that there are no password strength requirements in place. Because of this vulnerability, passwords might be easily discovered using a brute force attack. Which of the following password requirements will MOST effectively improve the security posture of the application against these attacks? (Select two)

Options

  • AMinimum complexity
  • BMaximum age limit
  • CMaximum length
  • DMinimum length
  • EMinimum age limit
  • FMinimum re-use limit

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#password policy#brute force attacks#password complexity#authentication hardening
Full SY0-501 Practice