What Most Effectively Reduces Brute Force Attack Success?
Which of the following MOST effectively reduces the probability of a brute force attack being successful?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your ability to prioritize direct attack interruption over password complexity, with the common trap being confusing longer passwords (which increase effort) with immediate access denial.
Account lockout policies are widely recognized as the most effective control against brute force attacks. Community consensus and official CISA guidance confirm that limiting login attempts directly interrupts automated guessing.
Option D (requiring minimum password length) is frequently chosen because stronger passwords do increase cracking time, but they fail to actively block or stop an ongoing brute force attempt like a lockout policy does.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Account lockout policies immediately disable credentials after a defined number of failed attempts, directly halting the iterative guessing process inherent to brute force attacks. By cutting off access, the probability of success drops to near zero regardless of underlying password complexity. This aligns with ISACA’s focus on practical, high-impact authentication controls that provide real-time prevention.Why the Other Options Are Wrong
Minimum password length (D) expands the key space but does not prevent rapid, automated trials during an active session. Increasing password change frequency (C) only mitigates long-term compromise risks, not real-time guessing. Activity timeouts (B) manage idle sessions and data leakage, offering no defense against repeated login attempts.Community Comment Notes
Users consistently validate A as the definitive ISACA answer, noting that while longer passwords improve theoretical security, lockouts provide immediate operational protection. One contributor emphasizes that “in reality and practice the answer is always A,” reflecting exam patterns where interrupting the attack vector trumps cryptographic hardening. Another clarifies that lockout policies directly limit the attempt window, making brute force economically unviable for attackers.Official Reference
Exam Strategy
When CISA questions ask for the 'MOST effective' control against an active attack, prioritize mechanisms that immediately interrupt or block the attack vector over those that merely increase attacker effort. Always evaluate options based on real-time prevention rather than long-term risk reduction.
Frequently Asked Questions
Why isn't longer password length the best defense against brute force?
Longer passwords increase cracking time but do not stop active guessing attempts. Lockout policies immediately block further trials, making them operationally superior for real-time prevention.
Does CISA consider account lockout better than multi-factor authentication here?
MFA prevents brute force entirely, but this question focuses on traditional password controls. Among the given options, lockout provides the most direct and immediate interruption.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →