Courseiva

CRISC Information Technology and Security Practice Question

An organization is implementing a new identity and access management (IAM) system. The risk practitioner is asked to identify the control that would BEST reduce the risk of unauthorized access due to compromised user credentials.

⚠ Common exam trap

The trap here is assuming that strong password policies or user training alone can prevent unauthorized access, overlooking that stolen credentials can bypass these measures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing multi-factor authentication (MFA) for all user accounts.

Multi-factor authentication (MFA) is the most effective control to reduce the risk of unauthorized access from compromised credentials because it requires an additional factor that an attacker is unlikely to possess. Password policies, training, and account lockout are useful but do not prevent access when valid credentials are stolen and used. MFA directly addresses the risk by adding a barrier that cannot be overcome with the password alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enforcing a strong password policy with complexity and expiration requirements.

    Why it's wrong here

    A strong password policy helps against brute-force and guessing attacks, but it does not prevent unauthorized access if credentials are stolen through phishing, malware, or data breaches. Passwords can still be compromised. While important, it is not the most effective control against credential compromise. Modern attacks often bypass password complexity by stealing credentials directly.

  • ✓

    Implementing multi-factor authentication (MFA) for all user accounts.

    Why this is correct

    MFA requires an additional factor beyond a password, such as a token or biometric, making it significantly harder for an attacker to gain access even if the password is compromised. This directly mitigates the risk of unauthorized access due to stolen credentials. It is the most effective control because it adds a layer that cannot be easily replicated by an attacker who only has the password.

  • ✗

    Implementing account lockout after three failed login attempts.

    Why it's wrong here

    Account lockout mitigates brute-force attacks but does not protect against the use of valid credentials obtained through other means. If an attacker has the correct password, lockout policies are irrelevant because the login will succeed. This control addresses a different threat vector and is not effective against compromised credentials that are used successfully on the first attempt.

  • ✗

    Conducting regular security awareness training for all employees.

    Why it's wrong here

    Security awareness training can reduce the likelihood of phishing and social engineering, but it does not prevent credential compromise from other vectors such as malware or third-party breaches. It is a preventive measure that relies on human behavior, which is not always reliable. Training alone cannot stop an attacker who already has valid credentials from accessing the system.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.