easyMultiple ChoiceObjective-mapped
SSCP Ensure that users cannot share passwords Practice Question
An administrator wants to ensure that users cannot share passwords. Which control is most effective at reducing the risk of password sharing?
⚠ Common exam trap
Candidates often choose password complexity or account lockout policies because they associate them with 'stronger security,' but they fail to recognize that these controls do not address the specific threat of voluntary password sharing, which MFA directly mitigates by adding an independent authentication factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multifactor authentication
Multifactor authentication (MFA) is the most effective control because it requires users to present two or more distinct factors (e.g., something you know, something you have, something you are) to authenticate. Even if a user shares their password (something you know), an attacker cannot authenticate without the second factor (e.g., a one-time passcode from a hardware token or biometric). This directly reduces the risk of password sharing by making the shared credential insufficient for access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Account lockout policies
Why it's wrong here
Account lockout protects against brute-force attempts, not password sharing.
- ✓
Multifactor authentication
Why this is correct
MFA requires a second factor that is often physical or biometric, making it difficult to share credentials.
- ✗
Password complexity
Why it's wrong here
Complex passwords are harder to guess but can still be shared.
- ✗
Password history
Why it's wrong here
Password history prevents reuse of old passwords, not sharing of current ones.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.