Courseiva

CISM Information Security Program Practice Question

An organization has implemented a new security policy requiring multi-factor authentication for all remote access. Several users complain about the inconvenience. What is the BEST course of action for the security manager?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Provide training on the importance of MFA

Providing training helps users understand the necessity of MFA for security, addressing their concerns and gaining buy-in. Allowing exceptions (A) weakens security, delaying implementation (B) postpones protection, and revoking access (C) is too punitive as a first step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow exceptions for senior executives

    Why it's wrong here

    Exceptions for senior executives create privileged accounts that bypass the policy, undermining its enforcement and setting a precedent attackers target. The policy exists to protect all remote access equally. A tempting route when executives resist, but the correct response is user education and change management, not weakening controls for rank.

  • ✗

    Delay implementation until user acceptance improves

    Why it's wrong here

    Deferring the control until complaints subside leaves remote access without MFA, extending exposure to credential-based attacks; user inconvenience does not alter the risk. Delay suits piloting controls where rollout risk outweighs threat, not a mandated authentication requirement.

  • ✗

    Revoke remote access for non-compliant users

    Why it's wrong here

    Revoking access for complainers punishes users instead of addressing the inconvenience driving non-compliance, harming operations without improving security outcomes. The policy's goal is adoption, not exclusion. Revocation is appropriate only for users who actively refuse after education and enforcement escalation, not as a first response to complaints.

  • ✓

    Provide training on the importance of MFA

    Why this is correct

    User resistance to MFA typically stems from unfamiliarity rather than the control itself. Training explains the rationale and correct enrolment, improving compliance without weakening the policy. Removing or exempting MFA would undermine the remote-access protection the organisation mandated.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.