Courseiva
easyMultiple Choice

SSCP Ensure that users cannot share passwords Practice Question

An administrator wants to ensure that users cannot share passwords. Which control is most effective at reducing the risk of password sharing?

⚠ Common exam trap

Candidates often choose password complexity or account lockout policies because they associate them with 'stronger security,' but they fail to recognize that these controls do not address the specific threat of voluntary password sharing, which MFA directly mitigates by adding an independent authentication factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multifactor authentication

Multifactor authentication (MFA) is the most effective control because it requires users to present two or more distinct factors (e.g., something you know, something you have, something you are) to authenticate. Even if a user shares their password (something you know), an attacker cannot authenticate without the second factor (e.g., a one-time passcode from a hardware token or biometric). This directly reduces the risk of password sharing by making the shared credential insufficient for access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Account lockout policies

    Why it's wrong here

    Lockout thresholds trigger on failed authentication attempts, so a colleague who already knows the password signs in successfully and never trips them. Lockout is designed to blunt brute-force and credential-stuffing attacks; it would be the right control when the risk is repeated guessing, not voluntary sharing.

  • ✓

    Multifactor authentication

    Why this is correct

    Multifactor authentication reduces password sharing because a stolen or shared password alone no longer grants access; the second factor, such as a push notification or FIDO2 key, stays bound to the legitimate user's device. This directly satisfies the stem's constraint of preventing users from sharing credentials successfully.

  • ✗

    Password complexity

    Why it's wrong here

    Complexity rules constrain password format only; users can still disclose a compliant password to a colleague, so sharing risk is unchanged. Complexity is the right control against brute-force and dictionary guessing, not against deliberate credential sharing.

  • ✗

    Password history

    Why it's wrong here

    Password history only prevents a user from reusing their own previous passwords at change time; it records nothing about who types the credential. It is the right control when the requirement is stopping cyclic reuse of old passwords, not detecting concurrent use of one credential by several people.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.