CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
After several employee accounts were compromised through phishing attacks that captured only usernames and passwords, a company's security team implements a requirement that users must also enter a one-time code generated by a mobile app before accessing cloud resources. This change strengthens which component of the identity and access management (IAM) process?
- AIdentification
- BAuthentication
- CAccounting
- DAuthorization
Show answer & explanationAnswer & explanation
Correct answer: B. Authentication
Requiring a one-time code in addition to a password is multi-factor authentication (MFA), which strengthens the authentication step—the process of verifying that a user is who they claim to be—by adding a second independent factor.
Why the other options are wrong
- A. Identification is the initial claim of identity (e.g., entering a username), not the verification step.
- C. Accounting tracks and logs user activity, unrelated to verifying identity at login.
- D. Authorization determines what an authenticated user is permitted to do, not how identity is verified.
Authentication (IAM)
The IAM process step that verifies a user's claimed identity, commonly strengthened through multi-factor authentication (MFA) combining something you know, have, or are.
- MFA reduces risk from stolen passwords alone
- Distinct from authorization, which controls access rights
- Part of the Identification-Authentication-Authorization-Accounting (IAAA) model
Memory trick: MFA = a second lock added to the authentication door