Courseiva
easyMultiple Choice

200-201 Practice Question: During a security audit, an analyst discovers…

During a security audit, an analyst discovers that several employees have shared their login credentials with colleagues to expedite work. Which policy enforcement mechanism would be most effective in preventing this behavior?

⚠ Common exam trap

Watch out — candidates often choose security awareness training (Option D) because it seems like a logical educational fix, but Cisco tests the distinction between administrative controls (training) and technical enforcement mechanisms (MFA) that actually prevent the behavior at the authentication layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement multi-factor authentication.

Multi-factor authentication (MFA) is the most effective enforcement mechanism because it requires a second factor (e.g., a one-time passcode from an authenticator app, a hardware token, or a biometric) in addition to the password. Even if employees share their passwords, MFA prevents unauthorized access because the second factor is tied to the individual's device or identity and cannot be easily shared. This directly addresses the root cause of credential sharing by making shared credentials useless without the additional factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a password complexity policy.

    Why it's wrong here

    Complexity rules only make a shared password harder to guess; they do nothing to detect or prevent two users authenticating with the same credential. Password complexity belongs in a baseline hardening standard, not as the control that addresses deliberate credential sharing.

  • ✓

    Implement multi-factor authentication.

    Why this is correct

    Multi-factor authentication binds each login to a second factor the colleague lacks, so a shared password alone no longer grants access. This directly defeats credential sharing, which password policies or awareness training cannot reliably prevent.

  • ✗

    Enforce a password change policy every 30 days.

    Why it's wrong here

    Forcing a 30-day password change does not stop two people from knowing the same credential; both can still authenticate. Rotation policies exist to limit the useful lifetime of a compromised secret, which is a different threat from deliberate credential sharing between colleagues.

  • ✗

    Conduct annual security awareness training.

    Why it's wrong here

    Annual awareness training changes behaviour through education but enforces nothing technically; shared credentials still authenticate successfully. Training is the right choice for building general security culture, yet the stem asks for an enforcement mechanism that actually prevents the behaviour.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.