Courseiva
mediumMultiple Choice

CISA Practice Question: Refer to the exhibit

Exhibit

Configuration snippet from a Windows server security policy:
Password Policy:
Enforce password history: 5 passwords remembered
Maximum password age: 90 days
Minimum password age: 1 day
Minimum password length: 8 characters
Complexity requirements: Enabled
Account Lockout Policy:
Account lockout threshold: 5 invalid logon attempts
Account lockout duration: 15 minutes
Reset account lockout counter after: 15 minutes

Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?

⚠ Common exam trap

Test-takers frequently confuse password history with password age settings, thinking that increasing the maximum password age or minimum password age will prevent reuse, when in fact only password history directly blocks the use of previously used passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the password history to 10

Increasing the password history setting (e.g., to 10) prevents users from reusing their most recent passwords by storing a specified number of previous password hashes. When a user attempts to change their password, the system compares the new password against the stored history and rejects it if it matches any of the remembered passwords. This directly addresses the weakness of easy password reuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Increase the password history to 10

    Why this is correct

    Password history records previously used hashes, so raising it to 10 prevents users from cycling back to any of their last ten passwords. This directly blocks the reuse weakness the auditor identified, forcing genuinely new credentials at each change.

  • ✗

    Increase the minimum password age to 7 days

    Why it's wrong here

    Minimum password age prevents users from cycling rapidly through the history requirement to return to a prior password; raising it to seven days does not stop reuse of a password still within the remembered history. It is tempting because it blocks fast password-cycling, and would be correct where users reset repeatedly within a single day to defeat history enforcement.

  • ✗

    Enable password expiration notifications

    Why it's wrong here

    Notifications merely warn users that a password is nearing expiry; they do not record or compare prior passwords, so reuse remains possible. It is tempting because it is a common hygiene setting, and would be correct where the weakness is users being surprised by expiry and choosing weak replacements at short notice.

  • ✗

    Increase the maximum password age to 30 days

    Why it's wrong here

    Maximum password age forces periodic changes but leaves the password history depth untouched, so a user can still set a previously used password. It is tempting because it is a standard password-policy control, and would be correct where the weakness is stale credentials remaining valid indefinitely rather than reuse of old passwords.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.