hardMultiple ChoiceObjective-mapped
Enforce MFA for All Users in Cloud SSO
During an audit, an IS auditor finds that the organization uses a cloud-based identity provider (IdP) for single sign-on (SSO) but does not enforce multi-factor authentication (MFA) for all users. Which of the following is the BEST recommendation to reduce risk?
Quick Answer
The answer is to enforce MFA for all users accessing any application. This is the best recommendation because a cloud-based identity provider (IdP) for single sign-on (SSO) creates a single trust boundary; if one password is compromised, an attacker gains access to every integrated application, so universal multi-factor authentication implementation is the only control that directly mitigates credential theft across the entire environment. On the CISA exam, this tests your understanding of access control in cloud SSO architectures and the principle of universal enforcement—a common trap is recommending MFA only for external-facing apps, which leaves internal applications vulnerable. Remember the memory tip: “One key opens every door, so lock every door with a second key.”
⚠ Common exam trap
Watch out — candidates often choose Option A (MFA only for external-facing apps) because they mistakenly believe internal apps are safe behind a corporate network perimeter, failing to recognize that cloud-based SSO eliminates network boundaries and that the IdP is the single point of authentication for all apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce MFA for all users accessing any application
Enforcing MFA for all users accessing any application is the best recommendation because it directly addresses the lack of a second authentication factor, which is the primary control to mitigate credential theft and unauthorized access. In a cloud-based IdP SSO environment, a single compromised password grants access to all integrated applications, so MFA must be applied universally to protect the entire trust boundary, not just external-facing apps. This aligns with NIST SP 800-63B and zero-trust principles, ensuring that every authentication request is verified with something the user knows and something they have.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require MFA only for external-facing applications
Why it's wrong here
Internal threats remain unaddressed.
- ✗
Disable SSO and require separate passwords for each application
Why it's wrong here
Would increase password fatigue and likely reduce security.
- ✗
Reduce session timeout to 15 minutes
Why it's wrong here
Does not prevent credential compromise.
- ✓
Enforce MFA for all users accessing any application
Why this is correct
Comprehensive MFA reduces risk of unauthorized access.
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a security assessment, an auditor discovers that employees are sharing passwords to access a critical system. Which of the following controls would BEST mitigate this risk?
easy- A.Provide security awareness training
- ✓ B.Implement multi-factor authentication
- C.Log all authentication attempts
- D.Enforce complex password policies
Why B: Multi-factor authentication (MFA) mitigates the risk of password sharing because even if credentials are shared, an attacker cannot authenticate without the second factor (e.g., a one-time passcode from a hardware token or authenticator app). MFA decouples authentication from a single shared secret, making shared passwords insufficient for access. This directly addresses the root cause—reliance on passwords alone—rather than attempting to prevent sharing behavior.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.