CompTIA Tech+ (FC0-U71)SecurityEasy
A user is attempting to log in to an online banking portal. After entering their username and password, the system prompts them to enter a six-digit code sent to their registered mobile phone. This authentication method is an example of which of the following?
- APasswordless authentication
- BSingle sign-on (SSO)
- CMulti-factor authentication (MFA)
- DBiometric authentication
Show answer & explanationAnswer & explanation
Correct answer: C. Multi-factor authentication (MFA)
Multi-factor authentication (MFA) requires a user to provide two or more different types of verification factors to gain access to an account. In this scenario, the password (something you know) and the code from the phone (something you have) represent two distinct factors.
Why the other options are wrong
- A. Passwordless authentication removes the need for a traditional password, often using biometrics or FIDO keys.
- B. Single sign-on (SSO) allows a user to log in once and gain access to multiple independent software systems.
- D. Biometric authentication uses unique physical characteristics, such as fingerprints or facial recognition.
Multi-Factor Authentication (MFA)
A security system that requires two or more distinct forms of authentication to verify a user's identity for a login or other transaction.
- Combines different 'factors': knowledge, possession, inherence.
- Greatly enhances security beyond just a password.
- Commonly uses a password plus a code from a device.
Memory trick: MFA: More Factors, More Secure Access.