What Should Be Included in an Improved Password Authentication Policy?
A security analyst needs to improve the company’s authentication policy following a password audit. Which of the following should be included in the policy? (Choose two.)
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question evaluates knowledge of password-specific policy parameters, with the common trap being the confusion between password composition rules and broader multi-factor authentication (MFA) or access control principles.
This SY0-701 practice question tests foundational password management controls, specifically focusing on length and complexity requirements. Community consensus strongly confirms that both options must be selected to align with modern security standards and pass the exam.
Candidates frequently select only Length or get distracted by MFA-related options like Something you have or Security keys. This happens because test-takers conflate general authentication improvements with specific password policy directives, overlooking that password rules govern character count and composition rather than hardware tokens or privilege levels.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Password Policy Fundamentals
When a security analyst reviews and improves a password policy, the primary technical controls focus on how passwords are constructed and validated. Length is universally recognized as the most critical factor in password strength, as it exponentially increases the attack surface for brute-force and dictionary attacks. Complexity complements length by enforcing a mix of character types (uppercase, lowercase, numbers, and special symbols), which further mitigates predictable patterns and reduces susceptibility to credential stuffing.
Why Other Options Are Incorrect
- Least privilege (C) is an access control principle, not a password configuration rule. It dictates that users should only have the minimum access necessary to perform their duties, which falls under authorization policies rather than authentication credentials.
- Something you have (D) and Security keys (E) relate to multi-factor authentication (MFA) and hardware-based identity verification. While these significantly improve overall authentication security, they are distinct from the internal requirements of a password policy itself. A password policy defines what makes a password strong; MFA defines additional verification steps beyond the password.
Community Insights & Exam Context
Multiple community members noted that while the correct answers are undeniably A and B, some exam simulation platforms restrict selecting multiple choices per click, causing confusion. As one candidate observed, "It doesn’t let you choose two…answers are A and B if we are talking about password policy." Always read the instruction stem carefully: when it explicitly says "Choose two" regarding password attributes, prioritize length and complexity over broader security frameworks.
Official Reference
https://pages.nist.gov/800-63-3/sp800-63b.html https://www.comptia.org/training/books/security-sy0-701 https://csrc.nist.gov/pubs/sp/800-63/b/final
exam_strategy": "When questions specify 'password policy,' immediately filter out MFA components, hardware tokens, and access control principles. Focus strictly on attributes that govern how passwords are created, stored, and managed. If forced to choose multiple answers related to password strength, prioritize length and complexity over expiration or history unless explicitly requested.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →