Courseiva
mediumMultiple ChoiceObjective-mapped

CISA Practice Question: Refer to the exhibit

Exhibit

Configuration snippet from a Windows server security policy:
Password Policy:
Enforce password history: 5 passwords remembered
Maximum password age: 90 days
Minimum password age: 1 day
Minimum password length: 8 characters
Complexity requirements: Enabled
Account Lockout Policy:
Account lockout threshold: 5 invalid logon attempts
Account lockout duration: 15 minutes
Reset account lockout counter after: 15 minutes

Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?

⚠ Common exam trap

Test-takers frequently confuse password history with password age settings, thinking that increasing the maximum password age or minimum password age will prevent reuse, when in fact only password history directly blocks the use of previously used passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Increase the password history to 10

Increasing the password history setting (e.g., to 10) prevents users from reusing their most recent passwords by storing a specified number of previous password hashes. When a user attempts to change their password, the system compares the new password against the stored history and rejects it if it matches any of the remembered passwords. This directly addresses the weakness of easy password reuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increase the password history to 10

    Why this is correct

    Correct. A higher password history forces users to wait longer before reusing a password.

  • Increase the minimum password age to 7 days

    Why it's wrong here

    Minimum password age prevents rapid changes but does not prevent reuse after the minimum period.

  • Enable password expiration notifications

    Why it's wrong here

    Notifications remind users to change passwords but do not address reuse.

  • Increase the maximum password age to 30 days

    Why it's wrong here

    Shortening password age reduces password lifetime but does not prevent reuse.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.