What is the policy regarding reusing previous passwords?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

What is the policy regarding reusing previous passwords?

Explanation:
The concept being tested is password history enforcement: preventing reuse of recently used passwords. In PCI environments, a password policy typically remembers a set number of previous passwords and forbids creating a new one that matches any of them. Four previous passwords is a common threshold, so you can’t reuse any of those recent values. This strengthens security by stopping the simple rotation of a small password set and reducing risk if a password was compromised or captured. It works alongside other controls like minimum length and complexity to provide stronger overall protection. The other options would weaken security—reusing after a fixed number of changes, requiring supervision, or waiting a long period like 90 days—because they still allow cycling back to recent passwords or are not practical, scalable policies for PCI environments.

The concept being tested is password history enforcement: preventing reuse of recently used passwords. In PCI environments, a password policy typically remembers a set number of previous passwords and forbids creating a new one that matches any of them. Four previous passwords is a common threshold, so you can’t reuse any of those recent values. This strengthens security by stopping the simple rotation of a small password set and reducing risk if a password was compromised or captured. It works alongside other controls like minimum length and complexity to provide stronger overall protection. The other options would weaken security—reusing after a fixed number of changes, requiring supervision, or waiting a long period like 90 days—because they still allow cycling back to recent passwords or are not practical, scalable policies for PCI environments.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy