SSCP Security Operations and Administration Practice Question
A security administrator is implementing a policy that requires all employees to use a password manager and enable multi-factor authentication. This policy is BEST described as a:
⚠ Common exam trap
The trap is that candidates may confuse a password policy (which includes MFA as an authentication control) with a remote access policy, because MFA is often associated with VPN logins. However, the question explicitly states the policy applies to all employees, not just remote workers, so the correct classification is a password policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password policy
The policy requires all employees to use a password manager and enable multi-factor authentication, which directly governs the creation, storage, and authentication strength of user credentials. This is the core function of a password policy, as defined in security frameworks like NIST SP 800-53 (IA-5) and ISO 27001 (A.9.2.1). It specifically addresses password complexity, rotation, and MFA enforcement, not data classification or access methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data handling policy
Why it's wrong here
Data handling policy covers classification, storage, and transmission of data, not authentication requirements.
- ✓
Password policy
Why this is correct
A password policy defines rules for password creation, management, and authentication, including multi-factor authentication.
- ✗
Social media policy
Why it's wrong here
Social media policy governs acceptable use of social media, not password requirements.
- ✗
Remote access policy
Why it's wrong here
Remote access policy governs how employees connect to the corporate network remotely, not general password rules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.