Courseiva
Governance and Management of ITeasyMultiple ChoiceObjective-mapped

CISA Governance and Management of IT Practice Question

A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enforce the existing policy through disciplinary actions and additional training.

The best governance response is to enforce the existing policy through disciplinary actions and additional training (option B). This addresses the root cause of non-compliance—employee behavior—by reinforcing the policy and educating staff. Option A (implementing MFA) is a technical control that may reduce password sharing but does not address the governance aspect; it could be a supporting measure but not the primary governance response. Option C (reporting to regulatory authority) is premature because password sharing does not necessarily constitute a data breach; there is no evidence of actual exposure. Option D (revising the password policy to require more complex passwords) does not prevent sharing and may even increase it if passwords are harder to remember. Therefore, governance should focus on policy enforcement and training.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement multi-factor authentication to prevent password sharing.

    Why it's wrong here

    MFA mitigates but does not eliminate risk; governance still needs policy enforcement.

  • Enforce the existing policy through disciplinary actions and additional training.

    Why this is correct

    Enforcement and training are key governance controls.

  • Report the incident to the regulatory authority as a data breach.

    Why it's wrong here

    Password sharing is not a data breach; reporting is premature.

  • Revise the password policy to require more complex passwords.

    Why it's wrong here

    Complexity does not prevent sharing.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.