What Most Effectively Reduces Brute Force Attack Success?

Access Control & Authentication
Answer Correct answer: A — Implementing an account lockout policy immediately disables credentials after repeated failures, directly preventing successful brute force execution.

Which of the following MOST effectively reduces the probability of a brute force attack being successful?

  1. Establishing an account lockout policy Correct Answer
  2. Establishing account activity timeouts
  3. Increasing password change frequency
  4. Requiring minimum password length

Community Votes

A
83%
D
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your ability to prioritize direct attack interruption over password complexity, with the common trap being confusing longer passwords (which increase effort) with immediate access denial.

Account lockout policies are widely recognized as the most effective control against brute force attacks. Community consensus and official CISA guidance confirm that limiting login attempts directly interrupts automated guessing.

Option D (requiring minimum password length) is frequently chosen because stronger passwords do increase cracking time, but they fail to actively block or stop an ongoing brute force attempt like a lockout policy does.

Community Discussion (6 comments)

RS66 👍 3 Selected: A
A. Establishing an account lockout policy
Sibsankar 👍 2
A is lock
shalota2 👍 2
By locking an account after a certain number of unsuccessful login attempts, the probability of a brute force attack succeeding is significantly reduced. Attackers are limited in the number of attempts they can make before the account is locked, which makes brute force attacks impractical. I don't know how ISACA thinks about this but in reality and practice the answer is ALWASY A.
Swallows 👍 1 Selected: D
Requiring a minimum password length ensures that passwords are not easily guessable and increases the complexity of potential passwords, making them more resilient against brute force attacks. Longer passwords exponentially increase the time it would take for an attacker to successfully guess the correct combination, thus reducing the probability of a successful brute force attack. While an account lockout policy can deter attackers by limiting the number of login attempts, a strong password policy acts as a barrier against brute force attacks from the outset.
mdh717 👍 2 Selected: A
Establishing an account lockout policy (A) is the most effective method for reducing the probability of a brute force attack being successful. A brute force attack involves trying many passwords or passphrases with the hope of eventually guessing the correct one. An account lockout policy will lock the account after a certain number of failed login attempts, thereby preventing the attacker from continuing to try different password combinations. This policy directly interrupts the brute force attack process by not allowing the attacker unlimited attempts within a short period of time.
Sibsankar 👍 1
D is wrong, C is right

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Account lockout policies immediately disable credentials after a defined number of failed attempts, directly halting the iterative guessing process inherent to brute force attacks. By cutting off access, the probability of success drops to near zero regardless of underlying password complexity. This aligns with ISACA’s focus on practical, high-impact authentication controls that provide real-time prevention.

Why the Other Options Are Wrong

Minimum password length (D) expands the key space but does not prevent rapid, automated trials during an active session. Increasing password change frequency (C) only mitigates long-term compromise risks, not real-time guessing. Activity timeouts (B) manage idle sessions and data leakage, offering no defense against repeated login attempts.

Community Comment Notes

Users consistently validate A as the definitive ISACA answer, noting that while longer passwords improve theoretical security, lockouts provide immediate operational protection. One contributor emphasizes that “in reality and practice the answer is always A,” reflecting exam patterns where interrupting the attack vector trumps cryptographic hardening. Another clarifies that lockout policies directly limit the attempt window, making brute force economically unviable for attackers.

Official Reference

Exam Strategy

When CISA questions ask for the 'MOST effective' control against an active attack, prioritize mechanisms that immediately interrupt or block the attack vector over those that merely increase attacker effort. Always evaluate options based on real-time prevention rather than long-term risk reduction.

Frequently Asked Questions

Why isn't longer password length the best defense against brute force?

Longer passwords increase cracking time but do not stop active guessing attempts. Lockout policies immediately block further trials, making them operationally superior for real-time prevention.

Does CISA consider account lockout better than multi-factor authentication here?

MFA prevents brute force entirely, but this question focuses on traditional password controls. Among the given options, lockout provides the most direct and immediate interruption.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide