CompTIA Tech+ (FC0-U71)SecurityEasy
A company implements a new policy requiring employees to use a combination of their password, a fingerprint scan, and a one-time code from a mobile app to access sensitive systems. Which security concept does this policy BEST exemplify?
- ASingle Sign-On (SSO)
- BRole-Based Access Control (RBAC)
- CMulti-factor Authentication (MFA)
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: C. Multi-factor Authentication (MFA)
Multi-factor authentication requires a user to provide two or more different types of credentials to verify their identity, significantly enhancing security.
Why the other options are wrong
- A. SSO allows users to authenticate once and gain access to multiple systems without re-entering credentials, which is not what multiple factors achieve.
- B. RBAC assigns access permissions based on a user's role within an organization, which is also an authorization concept, not an authentication method.
- D. Least privilege only grants users the minimum access rights necessary to perform their job functions, which is about authorization, not authentication methods.
Multi-factor Authentication (MFA)
A security system that requires users to provide two or more different types of credentials to verify their identity before granting access.
- Combines 'something you know', 'something you have', 'something you are'
- Significantly increases security
- Commonly used for sensitive data access
Memory trick: Authentication needs factors, more means more secure.