CompTIA Tech+ (FC0-U71)SecurityMedium
A company is implementing a new policy for employee passwords. The policy states that passwords must be at least 14 characters long, include a mix of uppercase and lowercase letters, numbers, and special characters, and cannot be reused for at least 10 previous cycles. Which of the following password policy components is addressed by the 'cannot be reused for at least 10 previous cycles' requirement?
- APassword complexity
- BPassword expiration
- CPassword length
- DPassword history
Show answer & explanationAnswer & explanation
Correct answer: D. Password history
Password history is a policy setting that prevents users from reusing a certain number of their previous passwords. This prevents users from simply rotating between a small set of familiar passwords, thereby enhancing security.
Why the other options are wrong
- A. Password complexity refers to the types of characters (uppercase, lowercase, numbers, symbols) required.
- B. Password expiration requires users to change their password after a certain period.
- C. Password length refers to the minimum number of characters required for a password.
Password History
A security policy setting that prevents users from reusing a specified number of their previously used passwords, thereby forcing them to create genuinely new passwords over time.
- Enhances password security by preventing easy reuse.
- Typically configured as 'remember X previous passwords'.
- Works in conjunction with complexity and length requirements.
Memory trick: Password policies: CLHE - Complexity, Length, History, Expiration.