CompTIA Cloud+ (CV0-004)SecurityMedium

A company is implementing a new cloud application that requires strong authentication for privileged users. The security team wants to ensure that even if a user's password is compromised, access to critical resources remains protected. Which authentication mechanism, when combined with a strong password, provides the MOST effective additional layer of security?

  1. ASecurity questions
  2. BSingle Sign-On (SSO)
  3. CKnowledge-based authentication (KBA)
  4. DBiometric authentication
Show answer & explanation

Correct answer: D. Biometric authentication

Biometric authentication, as a form of multi-factor authentication, provides a strong additional layer of security beyond a password, as it relies on something the user 'is' rather than something they 'know' or 'have'.

Why the other options are wrong

  • A. Security questions are a form of KBA and are generally considered a weak second factor as answers can often be discovered or guessed, especially for privileged users.
  • B. SSO simplifies access but doesn't add an additional factor of authentication; it usually relies on the strength of the initial authentication.
  • C. KBA, like security questions, is 'something you know' and can often be vulnerable to social engineering or brute-force attacks if the answers are common or guessable.

Multi-Factor Authentication (MFA)

An authentication method that requires a user to provide two or more verification factors to gain access to a resource.

  • Combines factors from different categories: knowledge, possession, inherence.
  • Significantly reduces the risk of credential compromise.
  • Common forms include passwords, tokens, biometrics.

Memory trick: KISS: Knowledge, Inherence, Something you have.

More Security questions