Courseiva
Information Security ProgrammediumMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

A company's security program includes a policy that all employees must use strong passwords and change them every 90 days. However, the recent internal audit shows that 60% of employees have passwords that do not meet the strength requirements. What is the most effective corrective action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement technical controls to enforce password strength

Implementing technical controls, such as password complexity requirements and automated enforcement, ensures compliance without relying solely on user behavior. Option A is wrong because manual audits detect non-compliance but do not prevent it. Option B is wrong because training alone is insufficient to enforce policy. Option D is wrong because extending the password change interval does not address the root cause of weak passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct quarterly password audits with manual checks

    Why it's wrong here

    Audits are detective, not preventive.

  • Increase the frequency of security awareness training

    Why it's wrong here

    Training is important but does not enforce compliance.

  • Implement technical controls to enforce password strength

    Why this is correct

    Technical enforcement (e.g., complexity rules) ensures compliance.

  • Extend the password change interval to 180 days

    Why it's wrong here

    This weakens security and does not enforce strength.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.