Security Fundamentals // Lesson 04

Password Policy & Alternatives.

Describe password management, complexity and safer alternatives including MFA, certificates and biometrics.

LengthUniquenessMFACertificatesBiometrics
01 // Mental model

Start with the big picture.

Prioritise sufficient length, uniqueness, protected storage and compromise-driven changes.

CCNA focus: Complexity rules are only one part of policy. Length, uniqueness, MFA, secure recovery and monitoring often matter more than forcing predictable symbol substitutions.
02 // Building blocks

Know what each part does.

01

Password policy

Prioritise sufficient length, uniqueness, protected storage and compromise-driven changes.

02

Management

Use approved password managers, prohibit sharing and remove stale accounts promptly.

03

MFA

Combines independent factors: something known, possessed or inherent.

04

Password alternatives

Certificates and cryptographic keys can provide strong machine or user authentication without reusable shared secrets.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
Knowledge factorSomething you know, such as a password or PIN.
Possession factorSomething you have, such as a hardware key or authenticator device.
Inherence factorSomething you are, such as a biometric characteristic.
CertificateBinds an identity to a public key through a trusted issuer and validation process.
04 // Policy checklist

Policy checklist.

Minimum: long, unique passphrases
Storage: salted adaptive password hashing
Privileged access: phishing-resistant MFA where possible
Recovery: verified, logged and resistant to social engineering
Lifecycle: joiner/mover/leaver controls
Monitoring: alert on spraying, reuse and impossible travel

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Something you know, such as a password or PIN.
  • Something you have, such as a hardware key or authenticator device.
  • Something you are, such as a biometric characteristic.
  • Binds an identity to a public key through a trusted issuer and validation process.
Exam checkpoint: Complexity rules are only one part of policy. Length, uniqueness, MFA, secure recovery and monitoring often matter more than forcing predictable symbol substitutions.
06 // Check yourself

Password Policy & Alternatives quiz.

1. Which pair represents two different authentication factors?

2. What is a certificate used to bind?

3. What is a biometric factor?

4. Why must account recovery be secured?

5. Should passwords be reused across services?

Score: 0 / 5