200-201 Security Policies and Procedures Practice Question
A company's security policy requires that privileged accounts use multi-factor authentication for all administrative access. An auditor finds that a database administrator logs in with a username and password only, then uses a shared service account with a static password for automation. Which policy violation represents the greater risk to the organization?
⚠ Common exam trap
The trap here is focusing on the visible MFA policy breach while overlooking that a shared static credential removes attribution and persists far longer, making it the more dangerous exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The use of a shared service account with a static password
Shared static credentials used for automation create privileged access that cannot be attributed to a person, is seldom rotated, and is often embedded in scripts where it can be harvested. If exposed, the attacker gains persistent administrative access without MFA and without accountability, complicating containment and forensics. A named administrator missing MFA is serious but remains traceable and revocable, so the shared service account poses the greater organizational risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The use of a shared service account with a static password
Why this is correct
A shared static credential used for automation cannot be attributed to a specific person, is rarely rotated, and often spreads across scripts and configuration files where it can be harvested. If compromised, it grants persistent privileged access with no MFA and no clear accountability, making containment difficult. This combination of anonymity, persistence, and wide exposure represents the greater risk.
- ✗
The database administrator's lack of MFA on administrative login
Why it's wrong here
Missing MFA on the administrator's interactive login is a real weakness because a stolen password alone would grant access. However, the credential is tied to a named individual and can be rotated or disabled when that person leaves. The shared static service account presents a broader and less traceable exposure, making this violation significant but not the greater risk in this comparison.
- ✗
The absence of a password vault for the administrator
Why it's wrong here
A password vault improves credential management and rotation, but its absence is a control gap rather than the primary exposure here. The scenario's critical issue is a shared, static, unattributable credential granting privileged access. Focusing on vaulting would address hygiene while missing the more serious problem of non-repudiation and persistence associated with the shared service account.
- ✗
The failure to log administrative database sessions
Why it's wrong here
Logging administrative sessions supports detection and investigation, and its absence weakens visibility. However, the scenario does not state that logging is missing, and even perfect logs would not reduce the exposure created by a shared static credential that cannot be tied to an individual. The greater risk remains the unattributable, persistent privileged access.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.