easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A company's help desk receives many requests from…
A company's help desk receives many requests from users who have forgotten their passwords. Which solution is MOST effective in reducing these requests while maintaining security?
⚠ Common exam trap
Many candidates choose SSO (Option C) thinking it eliminates all password-related issues, but they overlook that SSO still requires a primary password and does not address forgotten-password requests for that single credential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a self-service password reset (SSPR) with identity verification.
Self-service password reset (SSPR) with identity verification directly addresses the root cause of help desk calls—forgotten passwords—by allowing users to reset their own passwords after proving their identity via pre-registered methods (e.g., SMS, security questions, or biometrics). This reduces operational overhead while maintaining security through multi-factor verification and policy enforcement, unlike options that weaken security or fail to address the frequency of resets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a self-service password reset (SSPR) with identity verification.
Why this is correct
Implement a self-service password reset (SSPR) with identity verification. — SSPR empowers users to reset forgotten passwords independently by leveraging pre-registered identity verification methods, such as multi-factor authentication (MFA) or security questions. This significantly reduces the volume of password reset requests directed to the help desk, freeing up their resources for more complex issues. The integrated identity verification ensures that only the legitimate user can perform the reset, maintaining security while improving operational efficiency.
- ✗
Increase the password expiration period to 180 days.
Why it's wrong here
Increase the password expiration period to 180 days. — Increasing the password expiration period to 180 days primarily reduces the frequency of *mandatory* password changes, which are system-enforced. However, it does not address the fundamental problem of users *forgetting* their passwords before the expiration period is reached. Furthermore, longer expiration periods can increase the window of vulnerability if a password is compromised, making it a poor security practice to extend without other compensating controls.
- ✗
Use single sign-on for all applications.
Why it's wrong here
Use single sign-on for all applications. — Single sign-on (SSO) streamlines user experience by allowing access to multiple applications with a single set of credentials, thereby reducing the *number* of passwords users must remember. While this lessens the overall password management burden, it does not provide a mechanism for users to *reset* their primary SSO password if it is forgotten. Consequently, a forgotten primary password still necessitates help desk intervention, unless an SSPR solution is integrated with the SSO identity provider.
- ✗
Reduce the password complexity requirements.
Why it's wrong here
Reduce the password complexity requirements. — Reducing password complexity requirements directly weakens the security posture of the organization by making passwords significantly easier for attackers to guess, brute-force, or crack. While it might seem to alleviate the burden of remembering complex passwords, it does not prevent users from forgetting them entirely and introduces severe vulnerabilities that far outweigh any perceived convenience. This approach fundamentally compromises security for a negligible operational benefit.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Policy enforcement
Policy enforcement is the process of implementing and ensuring compliance with defined security rules and configurations across an IT environment.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.