Complex passwords aren’t always better

Recently I’ve had the exam for the CompTIA Security+ Certification.

While practicing for the exam, I’ve had the following question.


My company offers consulting on how to prepare for TISAX, ISO27001, NIS2, CSMS and SOC2 audits.
Get in touch with us here: https://www.endpoint-cybersecurity.com/contact/

Q:When setting password rules, which of the following will lower the level of security of a network ?
A: Complex passwords that users can not remotely changed are randomly generated by the administrator and given to users

Why ?

Very simple, actually 🙂
Because the users will write these passwords on stickers and hang them on their monitors 🙂
So, IT guys, please make your life simpler and let the users to change the passwords.
There you must definitely enforce some policies !


© Copyright 2011 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca - Security & Technology


Want to work with me on this topic?
Check Endpoint Cybersecurity to see the consulting services we offer.

One thought on “Complex passwords aren’t always better

Comments are closed.