Your 90-day password rotation check passes on every account — what risk does it not cover?
answer
- green measures activity, not the attack
- two separate questions, one answer
- rotation does not touch phishing
- stolen session survives a new password
- leaver accounts and rotation are unrelated
basics
~20 sIt proves only that passwords change on schedule. It says nothing about phishing, stolen session tokens, or accounts that were never removed. A green control measures the activity someone wrote down, not the attack it was meant to stop.
solid answer
~40 sThe check measures one activity: that a password value was replaced within 90 days. The risk it was written for is account takeover, and the paths attackers actually use — phishing a password and the one-time code with it, replaying a stolen session token, an account that stayed live after the person left — are all untouched by rotation. Modern authentication guidance (NIST SP 800-63B) actually recommends against forced periodic rotation unless there is evidence of compromise, because it pushes people toward predictable mutations. So the honest reading of the green result is: this control is satisfied, and I still do not know whether account takeover is harder. Those are two separate questions, and a passing check only ever answers the first.
go deeper
Be ready to state plainly what the check literally verifies and then list two attack paths it leaves open. Naming phishing and a live session after a password change is enough at this level.
Explain why checkable controls drift toward activity metrics, and describe what an outcome-shaped check on the same threat would query instead.
Show you can hold the obligation and the gap together: the evidence is legitimate, the threat is not reduced, and here is the replacement control with its own check and its own evidence.
Own the reporting risk. When leadership reads a 98 percent pass rate as an assurance statement, the fix is a second reported axis, not a louder caveat in the appendix.
## The two questions a green check answers, and the one it does not Every automated compliance check answers exactly one question: **is the thing the control describes true right now?** People routinely read it as answering a second, much larger question: **is the risk this control exists for actually reduced?** Keeping those apart is the whole skill this topic tests. A 90-day password rotation check reads account metadata and asserts that every password was last set within 90 days. When it is green, the following is true: password values change on a schedule. The following is *not* established: - that an attacker cannot phish a password (and, in the same session, the one-time code that goes with it); - that a stolen session token or refresh token is useless — rotating the password after the theft does not necessarily invalidate a live session, and the attacker was already in; - that accounts belonging to people who left the company are gone; - that a password reused from a breached third-party site is not in circulation. Rotation was invented for a world of offline password databases and long-lived static credentials, where forcing a change bounded how long a leaked hash stayed useful. Current guidance has moved: **NIST SP 800-63B recommends verifiers do not require arbitrary periodic password changes**, and instead force a change only on evidence of compromise, because mandatory rotation reliably produces `Summer2026!` becoming `Autumn2026!`. So the control is not merely incomplete; the activity it mandates can make the underlying risk slightly worse while reporting green every quarter. ## The pattern, not the example Call it **satisfied but ineffective**: the check is correct, the run is green, the evidence is real, and the risk is untouched. It is not a bug. Nothing is broken and there is nothing to fix in any system — the defect is in the control's *definition*. It happens for a structural reason. Controls get written so they can be checked, and checkability selects hard for **activity metrics** — did a thing happen, on time, everywhere — over **outcome metrics**, which are harder to define and often need data the compliance function does not hold. 'Password changed within 90 days' is a query. 'Account takeover is hard' is not. A second control from the same family shows the same shape. 'Quarterly access review completed' is green when every manager clicked through a list of their reports' entitlements and pressed approve. It is genuinely useful when done well. It is also compatible with three leavers keeping access for six weeks, because the review is a snapshot on a 90-day cycle and joiner-mover-leaver failures happen on the day someone changes role. Two green controls, and the actual exposure — nobody has a phishing-resistant factor, and departures are not wired to deprovisioning — sits entirely between them. ## How to answer without sounding cynical Interviewers are not looking for 'compliance is theatre'. They are looking for someone who can hold both facts at once: 1. **The control is satisfied and the evidence is legitimate.** If a framework or a customer contract requires rotation, the green run is a real obligation met, and saying so is not a concession. 2. **The threat it names is not measurably reduced**, and here is what would reduce it: a phishing-resistant second factor on every privileged account, session revocation on password change, deprovisioning triggered by the HR leaver event rather than by a quarterly review, and alerting on impossible-travel or new-device sign-ins. The useful move is to name the threat first and then ask what a check on *it* would look like. For account takeover: what fraction of privileged accounts have a phishing-resistant factor enrolled, and how long does it take from a leaver event to access being revoked? Both are queryable, both have variance, and both go red when the risk gets worse — which is the property the rotation check lacks. ## What this is not Do not confuse it with a **broken** check (the query is wrong, or it passes because it silently matched nothing) or a **misscoped** one (it only ever looked at one directory). Those are defects in the implementation and you fix the check. Satisfied-but-ineffective means the check is a faithful implementation of a control that was aimed at the wrong thing, so the change you are asking for is to the wording of the control itself.
- If rotation is the wrong control, what would you replace it with?Controls aimed at the actual takeover paths: a phishing-resistant second factor enrolled on every privileged account, sessions and refresh tokens invalidated on credential change, deprovisioning triggered by the HR leaver event rather than a quarterly review, and screening new passwords against known-breached lists. Each of those is queryable, so each can be a check with evidence — and each goes red when the exposure actually grows, which the 90-day check never does.
- Does the green run still have any value?Yes, two kinds. It satisfies an obligation, which is real when a framework or a customer contract names rotation, and it proves the account inventory and the evidence pipeline work end to end. What it does not do is support a claim about account security. Reporting it as 'accounts are secure' rather than 'the rotation control is satisfied' is where the harm starts.
- How would you spot this pattern in a control you have never seen before?Read the control and ask what attack it names, then ask what an attacker would do differently if the control were satisfied everywhere. If the answer is 'nothing', it is measuring activity rather than outcome. A second tell is that the metric has no variance — a control that has been 100 percent green for eight quarters is either genuinely solved or is not measuring anything that moves.
A restaurant that proves it washed the floors every night. True, recorded, and no evidence at all about what is happening in the fridge.
saying these in an interview costs you the question
- Says a passing control means the risk is handled
- Treats rotation frequency as a measure of account security
- Argues 30-day rotation would close the gap
- Calls the check broken when the check is correct
- Dismisses the whole control as theatre with no replacement