exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 452 discussion

Actual exam question from CompTIA's CAS-004
Question #: 452
Topic #: 1
[All CAS-004 Questions]

The results of an internal audit indicate several employees reused passwords that were previously included in a published list of compromised passwords.

The company has the following employee password policy:



Which of the following should be implemented to best address the password reuse issue? (Choose two.)

  • A. Increase the minimum age to two days.
  • B. Increase the history to 20.
  • C. Increase the character length to 12.
  • D. Add case-sensitive requirements to character class.
  • E. Decrease the maximum age to 30 days.
  • F. Remove the complexity requirements.
  • G. Increase the maximum age to 120 days.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
3 weeks, 5 days ago
Selected Answer: BE
To address the password reuse issue effectively, the company should focus on strategies that prevent employees from reusing previously compromised passwords. The best solutions for this issue are: B. Increase the history to 20. Password history refers to how many previous passwords a user is prevented from reusing. By increasing the history requirement to 20, employees will not be able to reuse any of their last 20 passwords, including those that were compromised. This will make it much harder for employees to simply reuse old passwords and ensure they choose unique ones each time. E. Decrease the maximum age to 30 days. Password expiration forces employees to change their passwords regularly, and setting the maximum age to 30 days ensures that passwords are updated frequently. This reduces the risk of compromised passwords lingering in the system for too long. A shorter password expiration cycle, like 30 days, also encourages employees to adopt better security habits and creates more opportunities to ensure passwords are not reused from previous cycles.
upvoted 1 times
...
esojzuir
5 months, 3 weeks ago
Selected Answer: AB
AB make sense, first 2 days between password changes and 20 passwords remembered takes over 40 days to get to a point where you are using your original password. Nobody will keep changing passwords every day for a month and a half.
upvoted 1 times
...
23169fd
5 months, 4 weeks ago
Selected Answer: AB
A. Increase the minimum age to two days: Increasing the minimum age of passwords ensures that users cannot rapidly change their password multiple times to cycle back to their original password. By setting a minimum age, you enforce a delay between password changes, which helps prevent users from bypassing the password history policy. B. Increase the history to 20: Increasing the password history requirement means that users cannot reuse any of their last 20 passwords. This significantly reduces the likelihood of password reuse because users must remember or generate many more unique passwords before they can reuse an old one.
upvoted 2 times
...
EAlonso
5 months, 4 weeks ago
Selected Answer: AB
Forget B.
upvoted 1 times
...
EAlonso
5 months, 4 weeks ago
Selected Answer: A
https://security.stackexchange.com/questions/78758/what-is-the-purpose-of-the-password-minimum-age-setting Vulnerability: For example, if you configure the Enforce password history policy setting to ensure that users cannot reuse any of their last 12 passwords, but you do not configure the Minimum password age policy setting to a number that is greater than 0, users could change their password 13 times in a few minutes and reuse their original password. You must configure this policy setting to a number that is greater than 0 for the Enforce password history policy setting to be effective. Countermeasure: Configure the Minimum password age policy setting to a value of at least 2 days.
upvoted 1 times
...
isaphiltrick
6 months, 1 week ago
Selected Answer: AB
By increasing the minimum password age to two days (option A), employees are compelled to retain passwords longer before changing them, which discourages rapid cycling and potential reuse. Simultaneously, increasing the password history to 20 (option B) ensures that employees must use a broader set of passwords before reusing any, thereby reducing the risk associated with compromised passwords. These measures together strengthen the organization's password security posture and mitigate the identified password reuse issue effectively.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago