CISA Governance and Management of IT Practice Question
A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?
⚠ Common exam trap
CISA often tests the distinction between technical controls and governance/administrative responses — candidates gravitate toward technical fixes (MFA, complexity) when the scenario calls for policy enforcement and training.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce the existing policy through disciplinary actions and additional training.
Password sharing is a policy violation, not a technical control failure. The best governance response is to enforce the existing policy through disciplinary action and reinforce awareness via training, addressing the human/behavioral root cause while maintaining a documented compliance posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement multi-factor authentication to prevent password sharing.
Why it's wrong here
MFA authenticates each individual at login but does not prevent one employee from handing over credentials plus a token or approving another's prompt. MFA is the right control when the risk is stolen or guessed credentials rather than voluntary sharing.
- ✓
Enforce the existing policy through disciplinary actions and additional training.
Why this is correct
Password sharing breaches the existing policy, so governance demands enforcing that policy through disciplinary action plus further training. Technical controls alone cannot compel behaviour; accountability and awareness address the human factor HIPAA privacy compliance requires.
- ✗
Report the incident to the regulatory authority as a data breach.
Why it's wrong here
Password sharing among staff is a policy violation, not necessarily a reportable breach, since no confirmed unauthorised disclosure of patient data has occurred. Reporting to the regulator is correct once an actual impermissible use or disclosure of protected health information is confirmed.
- ✗
Revise the password policy to require more complex passwords.
Why it's wrong here
Complexity rules do not stop deliberate credential sharing, since employees simply pass the stronger password along; the governance gap is behavioural, not technical. Raising complexity is the right response when weak or brute-forceable passwords are the actual finding.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.