Courseiva
easyMultiple Choice

CISA Practice Question: During a security assessment, an auditor…

During a security assessment, an auditor discovers that employees are sharing passwords to access a critical system. Which of the following controls would BEST mitigate this risk?

⚠ Common exam trap

Watch out — candidates often confuse 'preventing password sharing' with 'detecting or discouraging it,' and choose awareness training or logging, when the only control that technically renders shared passwords useless is multi-factor authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement multi-factor authentication

Multi-factor authentication (MFA) mitigates the risk of password sharing because even if credentials are shared, an attacker cannot authenticate without the second factor (e.g., a one-time passcode from a hardware token or authenticator app). MFA decouples authentication from a single shared secret, making shared passwords insufficient for access. This directly addresses the root cause—reliance on passwords alone—rather than attempting to prevent sharing behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Provide security awareness training

    Why it's wrong here

    Training addresses awareness but leaves the shared-credential behaviour intact, since accountability still cannot be attributed to an individual. Training is the right control for reducing accidental policy violations, not for eliminating deliberate credential sharing on a critical system.

  • ✓

    Implement multi-factor authentication

    Why this is correct

    Password sharing defeats individual accountability, since the system cannot distinguish who acted. Multi-factor authentication requires a second factor tied to each user's device, so a shared password alone no longer grants access, directly mitigating the shared-credential risk identified in the assessment.

  • ✗

    Log all authentication attempts

    Why it's wrong here

    Logging authentication attempts records events after the fact but does not prevent concurrent sessions under one credential, so shared passwords remain usable. Audit logging is the correct choice for detecting and investigating suspicious access retrospectively. Preventing sharing needs per-user credentials or session controls that make a shared secret unusable by a second person.

  • ✗

    Enforce complex password policies

    Why it's wrong here

    Complex password policies constrain credential format, not credential sharing; two employees can still use one strong password. Such policies are the right control against brute-force and dictionary attacks on individual accounts. Mitigating sharing requires unique per-user credentials with authentication logs tying each session to one identity.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.