ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a redesign of a mobile-banking app's login flow, the security team proposes a 12-character password that must include three special characters and be changed every 30 days. Usability testing shows high abandonment rates and a surge in password-reset tickets. Which alternative best applies the psychological acceptability principle while still providing strong authentication?
Keep passwords but extend minimum length to 16 characters and relax rotation to every 90 days.
Add a CAPTCHA challenge after each successful credential entry to verify a human user.
Require users to accept system-generated passphrases stored locally in the app for automatic fill.
Replace passwords with FIDO2/WebAuthn passwordless authentication using platform or security-key authenticators.
Psychological acceptability requires controls that users can apply easily and correctly; otherwise they will resist or circumvent them. Adopting passwordless FIDO2/WebAuthn authenticators eliminates the cognitive burden of remembering complex, frequently changing passwords while offering phishing-resistant, cryptographically strong authentication. Lengthening the password or forcing system-generated passphrases leaves memorization pain points, and adding CAPTCHA increases friction without addressing the root cause of abandonment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIDO2/WebAuthn authentication?
Open an interactive chat with Bash
Why is psychological acceptability important in security?
Open an interactive chat with Bash
How does passwordless authentication enhance security compared to traditional passwords?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .