CompTIA Tech+ (FC0-U71)SecurityEasy

A company is implementing a new security policy that requires employees to use a combination of something they know (password) and something they have (security token) to access sensitive internal systems. This policy is an example of which security principle?

  1. AMulti-Factor Authentication (MFA)
  2. BRole-Based Access Control (RBAC)
  3. CLeast Privilege
  4. DSingle Sign-On (SSO)
Show answer & explanation

Correct answer: A. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to provide two or more different types of authentication factors (knowledge, possession, inherence) to verify their identity, as described by using a password (something they know) and a security token (something they have).

Why the other options are wrong

  • B. RBAC assigns permissions based on a user's role, not on the authentication method itself.
  • C. Least Privilege ensures users only have the minimum necessary access, not how they authenticate.
  • D. SSO allows users to log in once to access multiple applications but doesn't specify multiple factors for the initial login.

Multi-Factor Authentication (MFA)

A security system that requires a user to provide two or more verification factors to gain access to a resource.

  • Combines different types of authentication factors.
  • Enhances security by requiring more than one credential.
  • Factors include knowledge (password), possession (token), and inherence (biometrics).

Memory trick: MFA: Many Factors Augment security.

More Security questions