CompTIA Tech+ (FC0-U71)SecurityEasy
A company is implementing a new security policy that requires employees to use a combination of something they know (password) and something they have (security token) to access sensitive internal systems. This policy is an example of which security principle?
- AMulti-Factor Authentication (MFA)
- BRole-Based Access Control (RBAC)
- CLeast Privilege
- DSingle Sign-On (SSO)
Show answer & explanationAnswer & explanation
Correct answer: A. Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) requires users to provide two or more different types of authentication factors (knowledge, possession, inherence) to verify their identity, as described by using a password (something they know) and a security token (something they have).
Why the other options are wrong
- B. RBAC assigns permissions based on a user's role, not on the authentication method itself.
- C. Least Privilege ensures users only have the minimum necessary access, not how they authenticate.
- D. SSO allows users to log in once to access multiple applications but doesn't specify multiple factors for the initial login.
Multi-Factor Authentication (MFA)
A security system that requires a user to provide two or more verification factors to gain access to a resource.
- Combines different types of authentication factors.
- Enhances security by requiring more than one credential.
- Factors include knowledge (password), possession (token), and inherence (biometrics).
Memory trick: MFA: Many Factors Augment security.