Easy-to-guess passwords led to an account compromise. The current password policy requires at least 12 alphanumeric characters, one uppercase character, one lowercase character, a password history of two passwords, a minimum password age of one day, and a maximum password age of 90 days. Which of the following would reduce the risk of this incident from happening again? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Increasing the minimum password length to 14 characters., Including a requirement for at least one special character..
Why this is the answer
The incident was caused by easy-to-guess passwords. To reduce this risk, you need to make passwords harder to guess and crack. Increasing the minimum password length to 14 characters directly improves password strength by expanding the character set and increasing the time required for brute-force attacks. Similarly, including a requirement for at least one special character adds complexity, making passwords significantly more difficult to guess or crack through dictionary attacks or common brute-force methods. Upgrading the password hashing algorithm from MD5 to SHA-512 is a good security practice but protects stored passwords from database breaches, not from users choosing easy-to-guess passwords in the first place. Increasing the maximum password age to 120 days would allow users to keep the same password for longer, potentially increasing the risk of compromise if that password is weak. Reducing the minimum password length to ten characters or reducing the minimum password age to zero days would weaken, not strengthen, password security.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed