nerdexam
(ISC)2

CISSP · Question #1418

An organization has implemented a password complexity and an account lockout policy enforcing five incorrect logins tries within ten minutes. Network users have reported significantly increased…

The correct answer is A. Availability. The security principle that this company is affecting is availability, which is the ability of authorized users to access and use the resources and information of the system or network. By implementing a password complexity and an account lockout policy, the company is trying…

Submitted by yousef_jo· Mar 5, 2026Security Operations

Question

An organization has implemented a password complexity and an account lockout policy enforcing five incorrect logins tries within ten minutes. Network users have reported significantly increased account lockouts. Which of the following security principles is this company affecting?

Options

  • AAvailability
  • BIntegrity
  • CConfidentiality
  • DAuthentication

How the community answered

(30 responses)
  • A
    93% (28)
  • B
    3% (1)
  • D
    3% (1)

Explanation

The security principle that this company is affecting is availability, which is the ability of authorized users to access and use the resources and information of the system or network. By implementing a password complexity and an account lockout policy, the company is trying to enhance the security and authentication of the system or network, but it may also reduce the availability of the system or network for the legitimate users. If the users forget their passwords, or enter them incorrectly, or become victims of brute-force or denial-of-service attacks, they may be locked out of the system or network, and unable to perform their tasks or functions. Therefore, the company should balance the security and availability of the system or network, and consider the impact of the password and account lockout policy on the users and the business.

Topics

#availability#account lockout#security principles#CIA triad

Community Discussion

No community discussion yet for this question.

Full CISSP Practice