ITPEC IP April 2019 Question 37

Source exam: ITPEC IP April 2019Topic: Security

ITPEC IP April 2019 — Question 37 of 100

A password used for a business system should not be reused for private Internet services. If one service is breached or the password is captured, reuse lets an attacker try the same credential against other accounts, including the business system.

Answer (a)

Why not others:
- an initial or default password should be changed promptly

- rotating through a small prepared set merely reuses old passwords

- storing a password in a plaintext file exposes it to anyone or any malware that can read the file

Key rule: Use a unique strong password for each account and store credentials only through appropriately protected mechanisms such as a password manager.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.