mediumMultiple Choice
ISC2 CC Practice Question: A mid-sized company has a network with 200…
A mid-sized company has a network with 200 employees. The security team has implemented a policy that requires all employees to use complex passwords and change them every 60 days. However, the company has experienced multiple phishing attacks where employees have willingly provided their credentials to fake websites. The CEO wants to implement a more robust authentication method. The company uses Microsoft Active Directory and has a budget for new security tools. They also have a remote workforce. Which of the following is the BEST course of action to address the phishing risk?
⚠ Common exam trap
CC often tests whether candidates recognize that stronger passwords and training do not stop credential phishing, so distractors that sound like 'more security hygiene' (complexity, rotation, password managers) lure candidates away from the control that actually breaks the phishing kill chain: MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy multi-factor authentication (MFA) for all remote access and critical systems
MFA directly mitigates credential phishing because even if an employee surrenders their username and password to a fake site, the attacker cannot complete authentication without the second factor. It addresses the root cause (credential compromise via phishing) rather than symptoms, and it works for the remote workforce described. Given Active Directory and budget for new tools, deploying MFA to remote access and critical systems is the highest-impact control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase password complexity requirements and change frequency to every 30 days
Why it's wrong here
Rotating passwords more often does not stop credential harvesting, because the phished password is valid at the moment it is submitted; only a phishing-resistant second factor breaks that. It is tempting as a cheap hardening step, and would be correct where the risk is brute-force or credential-stuffing against reused passwords.
- ✗
Conduct annual phishing awareness training
Why it's wrong here
Annual training leaves a year-long gap and relies on users recognising increasingly convincing lures, so credentials still reach fake sites. It is tempting because awareness is a recognised control layer, and would be correct as a supporting measure alongside, not instead of, an authentication control that resists credential theft.
- ✓
Deploy multi-factor authentication (MFA) for all remote access and critical systems
Why this is correct
MFA defeats phishing because a stolen password alone is insufficient; the second factor blocks the attacker. It directly addresses willing credential disclosure across remote access and critical systems, satisfying the remote workforce constraint without relying on password complexity or rotation.
- ✗
Implement a password manager for all employees
Why it's wrong here
A password manager stores and autofills credentials, but it will still release the password into a convincing fake login page, so phishing succeeds. It is tempting because it improves password hygiene and uniqueness, and would be correct where the problem is weak or reused passwords rather than credential harvesting.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.