CompTIA A+ Core 2 (220-1202)SecurityMedium

A company is implementing a new policy for user authentication. They want to ensure that even if a user's password is stolen, unauthorized access is prevented. The policy requires users to provide their password, a one-time code from a mobile app, and a fingerprint scan for logging into critical systems. Which authentication concept is being implemented?

  1. ADirectory Services Integration
  2. BRole-Based Access Control (RBAC)
  3. CMulti-Factor Authentication (MFA)
  4. DSingle Sign-On (SSO)
Show answer & explanation

Correct answer: C. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires a user to provide two or more distinct types of credentials from different categories (something you know, something you have, something you are) to verify their identity. In this scenario, a password (something you know), a one-time code (something you have), and a fingerprint (something you are) are all being used.

Why the other options are wrong

  • A. Directory services integration involves connecting systems to a central directory for user management.
  • B. RBAC assigns permissions based on a user's role within an organization.
  • D. SSO allows a user to log in once and access multiple related systems without re-authenticating.

Multi-Factor Authentication (MFA)

An authentication method that requires a user to provide two or more verification factors to gain access to a resource.

  • Combines different categories of factors (knowledge, possession, inherence).
  • Significantly increases security against credential theft.
  • Common factors include passwords, tokens, biometrics.

Memory trick: MFA mixes what you know, have, and are to confirm identity.

More Security questions