CompTIA Tech+ (FC0-U71)SecurityMedium

A company is implementing a new policy for employee passwords. The policy states that passwords must be at least 12 characters long, contain a mix of uppercase and lowercase letters, numbers, and special characters. Additionally, employees cannot reuse any of their last 10 passwords. Which security control is being enforced by the 'cannot reuse any of their last 10 passwords' requirement?

  1. APassword Complexity
  2. BPassword Length
  3. CPassword History
  4. DAccount Lockout
Show answer & explanation

Correct answer: C. Password History

Password history is a security control that prevents users from reusing a set number of their previous passwords. This makes it harder for attackers to compromise accounts by guessing recently used or slightly modified old passwords.

Why the other options are wrong

  • A. Password complexity refers to the requirements for character types (uppercase, lowercase, numbers, special characters).
  • B. Password length refers to the minimum number of characters required for a password.
  • D. Account lockout temporarily disables an account after multiple failed login attempts, which is a different control.

Password History

A security control that tracks a user's previously used passwords and prevents them from reusing any of them within a specified number of cycles.

  • Prevents users from cycling through a few common passwords.
  • Increases password entropy over time.
  • Makes brute-force and dictionary attacks less effective against old passwords.

Memory trick: Strong passwords need length, complexity, and memory.

More Security questions