TechKnowSurge
NIST 800-53 IA-5 NIST 800-53 AC-7 NIST 800-53 IA-2 CompTIA Security+ 4.6 CompTIA Tech+ 6.5 NIST NICE K0830 NIST 800-53 AT-3 NIST CSF PR.AA-01 NIST CSF PR.AA-03 ISC2 CC 3.2
InteractiveSecurityFree

Password Policy Autopsy

Dissect TechKnowDJ's outdated password policy and flag the rules that quietly make passwords weaker.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

A password policy can be strict and still make passwords worse. That is the counterintuitive idea at the centre of this activity, and it is why so many organizations still run policies that were considered best practice fifteen years ago. You are the new IAM analyst at TechKnowDJ, and the password policy you have inherited was written by an IT manager who left in 2022. Your job is to read it rule by rule and click every rule that weakens security or trains staff into bad habits. Nine are planted. Some are obvious once you look: MFA made optional for the admin accounts, which are the accounts attackers want most; a VPN that lets anyone guess passwords forever; a shared admin password kept in a spreadsheet. Others are rules that sound tough. Passwords that expire every 60 days teach people to count, so Summer2026! becomes Fall2026!. A rule demanding a capital, a number and a symbol is satisfied by Password1!, one of the most common passwords there is. Blocking paste sounds careful but stops the company's own password manager from working, so people shorten their passwords to something they can type. Password hints and security questions give attackers a way around the password entirely. And IT's own habits set the tone: reading the same starting password to a room full of new hires tells everyone that sharing a password is fine and that this is what a good one looks like. The rules that are fine matter just as much, because a good policy keeps them: single sign-on so staff need one strong password instead of twenty weak ones, MFA on every account, a short pause after repeated failed sign-ins, a long minimum length, checking new passwords against lists of breached and common ones, a company password manager, changing a password when there is evidence it has been compromised, regular password audits with retraining for repeat offenders, and a proper identity check before the help desk resets anything. Submit and every fault is explained with the behavior it causes and the rule that should replace it, following the lesson and current NIST guidance.

What you'll learn

Aligned to

NIST 800-53
IA-5 Authenticator Management
AC-7 Unsuccessful Logon Attempts
IA-2 Identification and Authentication (Organizational Users)
AT-3 Role-Based Training
CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
CompTIA Tech+
6.5 Explain password best practices
NIST NICE
K0830 Knowledge of password policies and procedures
NIST CSF
PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization.
PR.AA-03 Users, services, and hardware are authenticated.
ISC2 CC
3.2 Understand logical access controls

Key terms

Password Policy
A set of organizational rules governing the creation, complexity, expiration, and management of user passwords to reduce security risk.
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Account Lockout Threshold
A security setting that limits the number of failed login attempts before an account is temporarily locked to prevent brute force attacks.
Password Manager
A secure application that stores and manages a user's passwords in an encrypted vault, requiring only one master credential for access. Password managers enable users to maintain strong, unique passwords for every account without memorizing them.
Passphrase
A sequence of words or a sentence used as a password, combining length and memorability to create a strong authentication credential.
Default Password
A generic, preset password assigned to a device or account during setup that has not been changed by the user, representing a significant security vulnerability.
Password Audit
The process of running password-cracking tools against an organization's encrypted password database to identify weak or insecure passwords.
Single Sign-On
SSO
An authentication process that allows a user to access multiple applications with one set of credentials.
Brute Force Attack
An attack method that systematically tries all possible combinations of passwords or keys until the correct one is found.
Password Spraying
An attack that attempts a single commonly used password against many different user accounts before moving to the next password, deliberately staying below account lockout thresholds to avoid detection.
Credential Stuffing
An automated attack in which stolen username and password pairs from one breached service are systematically tested against other services to gain unauthorized access. It exploits users who reuse passwords across multiple accounts.
Password Reuse
The poor security practice of using the same password across multiple accounts, increasing exposure if one account is compromised.

Topics

Interactive Spot The Error

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →