CompTIA A+ Core 2 (220-1202)SecurityMedium
A company is implementing a new policy for user authentication. They want to ensure that even if a user's password is stolen, unauthorized access is prevented. The policy requires users to provide their password, a one-time code from a mobile app, and a fingerprint scan for logging into critical systems. Which authentication concept is being implemented?
- ADirectory Services Integration
- BRole-Based Access Control (RBAC)
- CMulti-Factor Authentication (MFA)
- DSingle Sign-On (SSO)
Show answer & explanationAnswer & explanation
Correct answer: C. Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) requires a user to provide two or more distinct types of credentials from different categories (something you know, something you have, something you are) to verify their identity. In this scenario, a password (something you know), a one-time code (something you have), and a fingerprint (something you are) are all being used.
Why the other options are wrong
- A. Directory services integration involves connecting systems to a central directory for user management.
- B. RBAC assigns permissions based on a user's role within an organization.
- D. SSO allows a user to log in once and access multiple related systems without re-authenticating.
Multi-Factor Authentication (MFA)
An authentication method that requires a user to provide two or more verification factors to gain access to a resource.
- Combines different categories of factors (knowledge, possession, inherence).
- Significantly increases security against credential theft.
- Common factors include passwords, tokens, biometrics.
Memory trick: MFA mixes what you know, have, and are to confirm identity.