CompTIA A+ Core 2 (220-1202)SecurityMedium

A company is implementing a new policy for user authentication. They want to ensure that even if one authentication method is compromised, unauthorized access is still prevented. To achieve this, users will be required to provide something they know, something they have, and something they are. Which security concept is being implemented?

  1. AMulti-Factor Authentication (MFA)
  2. BSingle Sign-On (SSO)
  3. CBiometric Authentication
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: A. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to present at least two different types of authentication factors (knowledge, possession, inherence) to verify their identity, significantly enhancing security.

Why the other options are wrong

  • B. SSO allows users to log in once to access multiple systems but doesn't inherently require multiple factors for the initial login.
  • C. Biometric Authentication is a type of 'something you are' factor, but it's only one part of the multi-factor requirement.
  • D. RBAC assigns permissions based on a user's role, which is an authorization concept, not an authentication method.

Multi-Factor Authentication (MFA)

A security system that requires more than one method of authentication from independent categories of credentials to verify the user's identity for a login or other transaction.

  • Combines at least two different authentication 'factors'.
  • Factors include: something you know, something you have, something you are.
  • Significantly reduces the risk of unauthorized access.

Memory trick: More factors mean more secure access.

More Security questions