easyMultiple Choice
CISA Practice Question: During a security assessment, an auditor…
During a security assessment, an auditor discovers that employees are sharing passwords to access a critical system. Which of the following controls would BEST mitigate this risk?
⚠ Common exam trap
Watch out — candidates often confuse 'preventing password sharing' with 'detecting or discouraging it,' and choose awareness training or logging, when the only control that technically renders shared passwords useless is multi-factor authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement multi-factor authentication
Multi-factor authentication (MFA) mitigates the risk of password sharing because even if credentials are shared, an attacker cannot authenticate without the second factor (e.g., a one-time passcode from a hardware token or authenticator app). MFA decouples authentication from a single shared secret, making shared passwords insufficient for access. This directly addresses the root cause—reliance on passwords alone—rather than attempting to prevent sharing behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide security awareness training
Why it's wrong here
Training addresses awareness but leaves the shared-credential behaviour intact, since accountability still cannot be attributed to an individual. Training is the right control for reducing accidental policy violations, not for eliminating deliberate credential sharing on a critical system.
- ✓
Implement multi-factor authentication
Why this is correct
Password sharing defeats individual accountability, since the system cannot distinguish who acted. Multi-factor authentication requires a second factor tied to each user's device, so a shared password alone no longer grants access, directly mitigating the shared-credential risk identified in the assessment.
- ✗
Log all authentication attempts
Why it's wrong here
Logging authentication attempts records events after the fact but does not prevent concurrent sessions under one credential, so shared passwords remain usable. Audit logging is the correct choice for detecting and investigating suspicious access retrospectively. Preventing sharing needs per-user credentials or session controls that make a shared secret unusable by a second person.
- ✗
Enforce complex password policies
Why it's wrong here
Complex password policies constrain credential format, not credential sharing; two employees can still use one strong password. Such policies are the right control against brute-force and dictionary attacks on individual accounts. Mitigating sharing requires unique per-user credentials with authentication logs tying each session to one identity.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.