Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A company's help desk receives many requests from…

A company's help desk receives many requests from users who have forgotten their passwords. Which solution is MOST effective in reducing these requests while maintaining security?

⚠ Common exam trap

Many candidates choose SSO (Option C) thinking it eliminates all password-related issues, but they overlook that SSO still requires a primary password and does not address forgotten-password requests for that single credential.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a self-service password reset (SSPR) with identity verification.

Self-service password reset (SSPR) with identity verification directly addresses the root cause of help desk calls—forgotten passwords—by allowing users to reset their own passwords after proving their identity via pre-registered methods (e.g., SMS, security questions, or biometrics). This reduces operational overhead while maintaining security through multi-factor verification and policy enforcement, unlike options that weaken security or fail to address the frequency of resets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement a self-service password reset (SSPR) with identity verification.

    Why this is correct

    Implement a self-service password reset (SSPR) with identity verification. — SSPR empowers users to reset forgotten passwords independently by leveraging pre-registered identity verification methods, such as multi-factor authentication (MFA) or security questions. This significantly reduces the volume of password reset requests directed to the help desk, freeing up their resources for more complex issues. The integrated identity verification ensures that only the legitimate user can perform the reset, maintaining security while improving operational efficiency.

  • Increase the password expiration period to 180 days.

    Why it's wrong here

    Increase the password expiration period to 180 days. — Increasing the password expiration period to 180 days primarily reduces the frequency of *mandatory* password changes, which are system-enforced. However, it does not address the fundamental problem of users *forgetting* their passwords before the expiration period is reached. Furthermore, longer expiration periods can increase the window of vulnerability if a password is compromised, making it a poor security practice to extend without other compensating controls.

  • Use single sign-on for all applications.

    Why it's wrong here

    Use single sign-on for all applications. — Single sign-on (SSO) streamlines user experience by allowing access to multiple applications with a single set of credentials, thereby reducing the *number* of passwords users must remember. While this lessens the overall password management burden, it does not provide a mechanism for users to *reset* their primary SSO password if it is forgotten. Consequently, a forgotten primary password still necessitates help desk intervention, unless an SSPR solution is integrated with the SSO identity provider.

  • Reduce the password complexity requirements.

    Why it's wrong here

    Reduce the password complexity requirements. — Reducing password complexity requirements directly weakens the security posture of the organization by making passwords significantly easier for attackers to guess, brute-force, or crack. While it might seem to alleviate the burden of remembering complex passwords, it does not prevent users from forgetting them entirely and introduces severe vulnerabilities that far outweigh any perceived convenience. This approach fundamentally compromises security for a negligible operational benefit.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.