Courseiva
mediumMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: A mid-sized company has a network with 200…

A mid-sized company has a network with 200 employees. The security team has implemented a policy that requires all employees to use complex passwords and change them every 60 days. However, the company has experienced multiple phishing attacks where employees have willingly provided their credentials to fake websites. The CEO wants to implement a more robust authentication method. The company uses Microsoft Active Directory and has a budget for new security tools. They also have a remote workforce. Which of the following is the BEST course of action to address the phishing risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy multi-factor authentication (MFA) for all remote access and critical systems

Multi-factor authentication (MFA) significantly reduces the risk of credential theft because even if a password is phished, the attacker cannot authenticate without the second factor. The other options either do not address phishing directly or are less effective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increase password complexity requirements and change frequency to every 30 days

    Why it's wrong here

    This does not prevent phishing; users will still give away complex passwords.

  • Conduct annual phishing awareness training

    Why it's wrong here

    Training is important but not as effective as MFA; phishing attacks are sophisticated.

  • Deploy multi-factor authentication (MFA) for all remote access and critical systems

    Why this is correct

    Correct. MFA adds a second layer that phished passwords cannot bypass.

  • Implement a password manager for all employees

    Why it's wrong here

    Password managers help with password hygiene but do not prevent phishing if the user still enters credentials into fake sites.

About these practice questions

This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.