Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A company's security policy requires that all…

A company's security policy requires that all employees use strong passwords and change them every 90 days. An employee writes their password on a sticky note and attaches it to their monitor. Another employee sees it and uses it to log into the first employee's account to send a fake email. The security team is conducting a post-incident review. Which security principle failed, and what is the most effective long-term solution to prevent this type of incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accountability; implement multi-factor authentication

The failure is a breach of accountability because the employee who shared the password and the one who used it without authorization violated the principle that actions should be traceable to individuals. The most effective long-term solution is to implement multi-factor authentication (B), which reduces the risk of password sharing and theft. Option A is wrong because annual security awareness training, while helpful, is often insufficient to change behavior long-term; Option C is wrong because prohibiting sticky notes is difficult to enforce and does not address the root cause; Option D is wrong because longer passwords do not prevent users from writing them down or sharing them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Integrity; conduct annual security awareness training

    Why it's wrong here

    Training is useful but often not enough to change behavior completely.

  • ✓

    Accountability; implement multi-factor authentication

    Why this is correct

    MFA ensures that a password alone is not sufficient for access.

  • ✗

    Availability; prohibit sticky notes in the office

    Why it's wrong here

    Prohibiting sticky notes is difficult to enforce and does not address the root cause.

  • ✗

    Confidentiality; enforce 15-character passwords

    Why it's wrong here

    Longer passwords help but don't prevent users from writing them down.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.