CompTIA A+ Core 2 (220-1202)SecurityMedium
A company's security policy states that all employees must be uniquely identified and their actions auditable. When a new employee joins, they are assigned a distinct username. This username, along with a password, is used to verify their identity before granting access to network resources. Which fundamental security concept is primarily being implemented here?
- AAuthorization
- BNon-repudiation
- CAccounting
- DAuthentication
Show answer & explanationAnswer & explanation
Correct answer: D. Authentication
The scenario describes the process of verifying a user's identity ('uniquely identified', 'distinct username', 'verify their identity before granting access') using credentials ('username, along with a password'). This directly corresponds to the definition of Authentication, which is the process of proving one's identity.
Why the other options are wrong
- A. Authorization determines *what* an authenticated user can access, not the process of proving who they are.
- B. Non-repudiation ensures that an action cannot be denied later, which is a result of effective authentication and accounting, but not the act of verifying identity itself.
- C. Accounting tracks *what* an authenticated user did, which comes after authentication and authorization.
Authentication
The process of verifying the identity of a user, process, or device. It typically involves providing credentials (e.g., username and password) that are then checked against a stored record.
- Verifies identity (who you are)
- Often uses username/password, biometrics, or tokens
- First step in the AAA (Authentication, Authorization, Accounting) process
- Ensures only legitimate users gain access
Memory trick: AAA: You Authenticate to prove who you are, then are Authorized for what you can do, and finally Accounted for what you did.