nerdexam
Isaca

CRISC · Question #428

Which of the following management actions will MOST likely change the likelihood rating of a risk scenario related to remote network access?

The correct answer is D. Implementing multi-factor authentication. Implementing multi-factor authentication (MFA) will most significantly change the likelihood rating of a remote network access risk scenario by strengthening the authentication process.

Submitted by yousef_jo· Apr 18, 2026Risk Response and Reporting

Question

Which of the following management actions will MOST likely change the likelihood rating of a risk scenario related to remote network access?

Options

  • ACreating metrics to track remote connections
  • BUpdating the organizational policy for remote access
  • CUpdating remote desktop software
  • DImplementing multi-factor authentication

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    15% (4)
  • C
    4% (1)
  • D
    73% (19)

Why each option

Implementing multi-factor authentication (MFA) will most significantly change the likelihood rating of a remote network access risk scenario by strengthening the authentication process.

ACreating metrics to track remote connections

Creating metrics helps to monitor and identify trends in remote connections but does not proactively reduce the likelihood of a security incident occurring.

BUpdating the organizational policy for remote access

Updating the organizational policy sets guidelines and requirements but does not inherently implement the technical controls that directly reduce the likelihood of an attack.

CUpdating remote desktop software

Updating remote desktop software primarily addresses known vulnerabilities within the software, which can reduce likelihood, but MFA directly strengthens the user authentication process regardless of software vulnerabilities, providing a more comprehensive likelihood reduction for access.

DImplementing multi-factor authenticationCorrect

Implementing multi-factor authentication (MFA) drastically increases the difficulty for an unauthorized party to gain access to remote networks, even if one authentication factor (like a password) is compromised. By requiring multiple forms of verification, MFA directly reduces the likelihood of a successful breach via remote network access by significantly raising the bar for unauthorized entry.

Concept tested: Risk reduction (likelihood) through MFA

Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks

Topics

#Risk Likelihood#Risk Response#Access Control#Multi-factor Authentication

Community Discussion

No community discussion yet for this question.

Full CRISC Practice