CompTIA A+ Core 2 (220-1202)SecurityMedium

A company's security policy states that all employees must be uniquely identified and their actions auditable. When a new employee joins, they are assigned a distinct username. This username, along with a password, is used to verify their identity before granting access to network resources. Which fundamental security concept is primarily being implemented here?

  1. AAuthorization
  2. BNon-repudiation
  3. CAccounting
  4. DAuthentication
Show answer & explanation

Correct answer: D. Authentication

The scenario describes the process of verifying a user's identity ('uniquely identified', 'distinct username', 'verify their identity before granting access') using credentials ('username, along with a password'). This directly corresponds to the definition of Authentication, which is the process of proving one's identity.

Why the other options are wrong

  • A. Authorization determines *what* an authenticated user can access, not the process of proving who they are.
  • B. Non-repudiation ensures that an action cannot be denied later, which is a result of effective authentication and accounting, but not the act of verifying identity itself.
  • C. Accounting tracks *what* an authenticated user did, which comes after authentication and authorization.

Authentication

The process of verifying the identity of a user, process, or device. It typically involves providing credentials (e.g., username and password) that are then checked against a stored record.

  • Verifies identity (who you are)
  • Often uses username/password, biometrics, or tokens
  • First step in the AAA (Authentication, Authorization, Accounting) process
  • Ensures only legitimate users gain access

Memory trick: AAA: You Authenticate to prove who you are, then are Authorized for what you can do, and finally Accounted for what you did.

More Security questions