CompTIA Cloud+ (CV0-004)SecurityMedium
A company is implementing a new cloud application that requires strong authentication for privileged users. The security team wants to ensure that even if a user's password is compromised, access to critical resources remains protected. Which authentication mechanism, when combined with a strong password, provides the MOST effective additional layer of security?
- ASecurity questions
- BSingle Sign-On (SSO)
- CKnowledge-based authentication (KBA)
- DBiometric authentication
Show answer & explanationAnswer & explanation
Correct answer: D. Biometric authentication
Biometric authentication, as a form of multi-factor authentication, provides a strong additional layer of security beyond a password, as it relies on something the user 'is' rather than something they 'know' or 'have'.
Why the other options are wrong
- A. Security questions are a form of KBA and are generally considered a weak second factor as answers can often be discovered or guessed, especially for privileged users.
- B. SSO simplifies access but doesn't add an additional factor of authentication; it usually relies on the strength of the initial authentication.
- C. KBA, like security questions, is 'something you know' and can often be vulnerable to social engineering or brute-force attacks if the answers are common or guessable.
Multi-Factor Authentication (MFA)
An authentication method that requires a user to provide two or more verification factors to gain access to a resource.
- Combines factors from different categories: knowledge, possession, inherence.
- Significantly reduces the risk of credential compromise.
- Common forms include passwords, tokens, biometrics.
Memory trick: KISS: Knowledge, Inherence, Something you have.