CompTIA Tech+ (FC0-U71)SecurityHard

A company requires employees to use strong passwords, defined as having at least 12 characters, including uppercase, lowercase, numbers, and special symbols. Additionally, passwords must be changed every 90 days. Which security policy element is NOT directly addressed by these requirements?

  1. APassword Length
  2. BPassword History
  3. CPassword Expiration
  4. DPassword Complexity
Show answer & explanation

Correct answer: B. Password History

Password history prevents users from reusing previous passwords, which is a separate requirement from complexity, length, or expiration and is not mentioned in the scenario.

Why the other options are wrong

  • A. Password length is addressed by requiring 'at least 12 characters'.
  • C. Password expiration is addressed by requiring passwords to be changed 'every 90 days'.
  • D. Password complexity is addressed by requiring uppercase, lowercase, numbers, and special symbols.

Password History

A security policy setting that prevents users from reusing a certain number of their most recent passwords, enhancing security by forcing unique passwords over time.

  • Prevents reuse of old passwords
  • Works with password expiration
  • Adds a layer of security against common password attacks

Memory trick: Passwords need policies, strong and ever-changing.

More Security questions