Courseiva
easyMultiple Choice

CAS-004 Practice Question: A company's risk assessment identifies that…

A company's risk assessment identifies that employees often use weak passwords. Which control directly addresses this risk?

⚠ Common exam trap

It's easy for candidates to confuse 'addressing the risk' with 'mitigating the impact'—MFA (Option C) reduces the impact of a weak password but does not prevent the weak password itself, which is the root cause identified in the risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce a strong password policy

Enforcing a strong password policy directly addresses the risk of weak passwords by mandating complexity, length, and expiration requirements (e.g., minimum 12 characters, mixed case, numbers, symbols). This control reduces the likelihood of successful brute-force or dictionary attacks by increasing the entropy of user credentials. Unlike other options, it specifically targets the root cause—weak password creation—rather than adding compensating controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct security awareness training

    Why it's wrong here

    Training changes user behaviour but does not enforce password strength; weak passwords remain permitted. It is tempting because awareness programmes address the human factor behind poor credential choices, and would be the right control where the risk is phishing susceptibility or unsafe handling rather than password composition itself.

  • ✗

    Deploy single sign-on

    Why it's wrong here

    Single sign-on centralises authentication but does not enforce password strength; a weak credential still grants access across every federated application. It is tempting because it reduces password sprawl and login friction, and would be the right control when the risk is credential fatigue or inconsistent identity management across many systems.

  • ✗

    Implement multi-factor authentication

    Why it's wrong here

    Multi-factor authentication adds a second verification factor but leaves the weak password itself valid, so it does not directly remediate the identified weakness. It is tempting because it substantially reduces account-takeover risk, and would be the correct control when the risk is credential theft or replay rather than password strength.

  • ✓

    Enforce a strong password policy

    Why this is correct

    Weak passwords stem from user behaviour, so a preventive administrative control is needed. Enforcing a strong password policy sets complexity, length and expiry requirements at authentication, directly removing the weak-credential risk rather than detecting it afterwards.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.