CISM Information Security Program Practice Question
An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide training on the importance of MFA
Providing training helps users understand the necessity of MFA for security, addressing their concerns and gaining buy-in. Allowing exceptions (A) weakens security, delaying implementation (B) postpones protection, and revoking access (C) is too punitive as a first step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow exceptions for senior executives
Why it's wrong here
Exceptions for senior executives create privileged accounts that bypass the policy, undermining its enforcement and setting a precedent attackers target. The policy exists to protect all remote access equally. A tempting route when executives resist, but the correct response is user education and change management, not weakening controls for rank.
- ✗
Delay implementation until user acceptance improves
Why it's wrong here
Deferring the control until complaints subside leaves remote access without MFA, extending exposure to credential-based attacks; user inconvenience does not alter the risk. Delay suits piloting controls where rollout risk outweighs threat, not a mandated authentication requirement.
- ✗
Revoke remote access for non-compliant users
Why it's wrong here
Revoking access for complainers punishes users instead of addressing the inconvenience driving non-compliance, harming operations without improving security outcomes. The policy's goal is adoption, not exclusion. Revocation is appropriate only for users who actively refuse after education and enforcement escalation, not as a first response to complaints.
- ✓
Provide training on the importance of MFA
Why this is correct
User resistance to MFA typically stems from unfamiliarity rather than the control itself. Training explains the rationale and correct enrolment, improving compliance without weakening the policy. Removing or exempting MFA would undermine the remote-access protection the organisation mandated.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.