The strength of a password is is difficulty to guess. A popular password cannot be strong.
What is misleading is that for the last 15 years now, stupid security has been around and promoting password with special characters, numbers, uppercase,
If your brute force cracker is as stupid as those meters, yes, it will be hard to find Password1!. But if you're running a list of common password or using state of the art deep learning to try to act as a human instead of a stupid algorithm, Password1! is immediate to find.
I was pissed off every time I saw a website with a stupid password meter or requirement 5 years ago. Finally some people try to stop this madness, but this will not be easy.