Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator is implementing a policy that requires all employees to use a password manager and enable multi-factor authentication. This policy is BEST described as a:

⚠ Common exam trap

The trap is that candidates may confuse a password policy (which includes MFA as an authentication control) with a remote access policy, because MFA is often associated with VPN logins. However, the question explicitly states the policy applies to all employees, not just remote workers, so the correct classification is a password policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password policy

The policy requires all employees to use a password manager and enable multi-factor authentication, which directly governs the creation, storage, and authentication strength of user credentials. This is the core function of a password policy, as defined in security frameworks like NIST SP 800-53 (IA-5) and ISO 27001 (A.9.2.1). It specifically addresses password complexity, rotation, and MFA enforcement, not data classification or access methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data handling policy

    Why it's wrong here

    Data handling policy covers classification, storage, and transmission of data, not authentication requirements.

  • ✓

    Password policy

    Why this is correct

    A password policy defines rules for password creation, management, and authentication, including multi-factor authentication.

  • ✗

    Social media policy

    Why it's wrong here

    Social media policy governs acceptable use of social media, not password requirements.

  • ✗

    Remote access policy

    Why it's wrong here

    Remote access policy governs how employees connect to the corporate network remotely, not general password rules.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.