ITPEC IP October 2024 Question 40
ITPEC IP October 2024 — Question 40 of 100
A password policy defines requirements such as permitted character types, minimum length, reuse restrictions, and related account-password rules. An organization or system applies the policy to promote passwords that are harder to guess or brute-force and may combine it with controls such as rate limiting and multifactor authentication.
Answer (c)
Why not others:
- (a) Single sign-on lets one authentication session provide access to multiple systems or services
- (b) Password crack means attempting to discover a password, not defining its requirements
- (d) One-time password is a password valid for only one login or a short period
Key rule: A password policy specifies how passwords must be constructed and managed; the other terms describe authentication mechanisms or attacks.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.