mediumMultiple Choice
CISA Practice Question: Refer to the exhibit
Exhibit
Configuration snippet from a Windows server security policy: Password Policy: Enforce password history: 5 passwords remembered Maximum password age: 90 days Minimum password age: 1 day Minimum password length: 8 characters Complexity requirements: Enabled Account Lockout Policy: Account lockout threshold: 5 invalid logon attempts Account lockout duration: 15 minutes Reset account lockout counter after: 15 minutes
Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?
⚠ Common exam trap
Test-takers frequently confuse password history with password age settings, thinking that increasing the maximum password age or minimum password age will prevent reuse, when in fact only password history directly blocks the use of previously used passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the password history to 10
Increasing the password history setting (e.g., to 10) prevents users from reusing their most recent passwords by storing a specified number of previous password hashes. When a user attempts to change their password, the system compares the new password against the stored history and rejects it if it matches any of the remembered passwords. This directly addresses the weakness of easy password reuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increase the password history to 10
Why this is correct
Password history records previously used hashes, so raising it to 10 prevents users from cycling back to any of their last ten passwords. This directly blocks the reuse weakness the auditor identified, forcing genuinely new credentials at each change.
- ✗
Increase the minimum password age to 7 days
Why it's wrong here
Minimum password age prevents users from cycling rapidly through the history requirement to return to a prior password; raising it to seven days does not stop reuse of a password still within the remembered history. It is tempting because it blocks fast password-cycling, and would be correct where users reset repeatedly within a single day to defeat history enforcement.
- ✗
Enable password expiration notifications
Why it's wrong here
Notifications merely warn users that a password is nearing expiry; they do not record or compare prior passwords, so reuse remains possible. It is tempting because it is a common hygiene setting, and would be correct where the weakness is users being surprised by expiry and choosing weak replacements at short notice.
- ✗
Increase the maximum password age to 30 days
Why it's wrong here
Maximum password age forces periodic changes but leaves the password history depth untouched, so a user can still set a previously used password. It is tempting because it is a standard password-policy control, and would be correct where the weakness is stale credentials remaining valid indefinitely rather than reuse of old passwords.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.