CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard

After several employee accounts were compromised through phishing attacks that captured only usernames and passwords, a company's security team implements a requirement that users must also enter a one-time code generated by a mobile app before accessing cloud resources. This change strengthens which component of the identity and access management (IAM) process?

  1. AIdentification
  2. BAuthentication
  3. CAccounting
  4. DAuthorization
Show answer & explanation

Correct answer: B. Authentication

Requiring a one-time code in addition to a password is multi-factor authentication (MFA), which strengthens the authentication step—the process of verifying that a user is who they claim to be—by adding a second independent factor.

Why the other options are wrong

  • A. Identification is the initial claim of identity (e.g., entering a username), not the verification step.
  • C. Accounting tracks and logs user activity, unrelated to verifying identity at login.
  • D. Authorization determines what an authenticated user is permitted to do, not how identity is verified.

Authentication (IAM)

The IAM process step that verifies a user's claimed identity, commonly strengthened through multi-factor authentication (MFA) combining something you know, have, or are.

  • MFA reduces risk from stolen passwords alone
  • Distinct from authorization, which controls access rights
  • Part of the Identification-Authentication-Authorization-Accounting (IAAA) model

Memory trick: MFA = a second lock added to the authentication door

More Governance, Risk, Compliance and Security questions