Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A company policy requires employees to use multi-factor authentication (MFA) for accessing corporate resources, including email and internal applications. This measure is primarily implemented to strengthen which aspect of security?

  1. AConfidentiality
  2. BAuthentication
  3. CNon-repudiation
  4. DAuthorization
Show answer & explanation

Correct answer: B. Authentication

Multi-factor authentication (MFA) is a method of verifying a user's identity by requiring multiple pieces of evidence, primarily strengthening the authentication process itself.

Why the other options are wrong

  • A. Confidentiality is the goal of protecting data, but MFA is a mechanism for identity verification, which then enables confidentiality.
  • C. Non-repudiation prevents denial of actions, which is different from verifying a user's identity at login.
  • D. Authorization determines what an authenticated user can do, not how they prove who they are.

Authentication

The process of verifying the identity of a user, process, or device before granting access to a system or resource.

  • Proves 'who you are'.
  • Often relies on something you know, have, or are.
  • Precedes authorization.

Memory trick: AAA: Authenticate first, Authorize next, then Audit.

More Security Principles questions