easyMultiple Choice
CISA Has a policy requiring strong passwords Practice Question
An organization has a policy requiring strong passwords. Which additional control is most effective at preventing credential stuffing attacks?
⚠ Common exam trap
CISA often tests the misconception that stronger passwords alone defeat credential stuffing, when the real gap is single-factor authentication — candidates who focus on password policy miss that the credentials are already valid.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requiring multi-factor authentication (MFA) for all logins.
Credential stuffing relies on reusing breached username/password pairs, so even strong, unique passwords can be valid if they were leaked elsewhere. MFA breaks the attack because possession of a stolen password alone is insufficient to authenticate; the attacker also needs the second factor, which they typically do not have.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increasing password length and complexity requirements.
Why it's wrong here
Length and complexity rules govern password creation, not authentication attempts; attackers replay credentials stolen elsewhere, so stronger composition never comes into play. It is tempting because password policy is the visible control in the stem, and it would be correct against offline cracking of a captured hash.
- ✗
Implementing account lockout after 3 failed attempts.
Why it's wrong here
Lockout after three failures blocks brute-force guessing against one account, but credential stuffing uses valid stolen pairs, so each attempt succeeds on the first try and no failure counter increments. It is tempting because lockout thresholds are a standard authentication hardening measure, and would be correct against online password guessing.
- ✓
Requiring multi-factor authentication (MFA) for all logins.
Why this is correct
Credential stuffing replays valid username and password pairs stolen elsewhere, so password strength alone cannot stop it. Requiring MFA for all logins adds a second factor the attacker lacks, blocking authentication even when the compromised credentials are correct.
- ✗
Conducting annual security awareness training.
Why it's wrong here
Awareness training changes user behaviour over time; it does not block automated replay of credentials already leaked and reused across services. It is tempting because training addresses phishing and weak user habits, and would be the right control for reducing social-engineering success rather than stopping credential stuffing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.