Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A company policy requires employees to use multi-factor authentication (MFA) for accessing corporate resources, including email and internal applications. This measure is primarily implemented to strengthen which aspect of security?
- AConfidentiality
- BAuthentication
- CNon-repudiation
- DAuthorization
Show answer & explanationAnswer & explanation
Correct answer: B. Authentication
Multi-factor authentication (MFA) is a method of verifying a user's identity by requiring multiple pieces of evidence, primarily strengthening the authentication process itself.
Why the other options are wrong
- A. Confidentiality is the goal of protecting data, but MFA is a mechanism for identity verification, which then enables confidentiality.
- C. Non-repudiation prevents denial of actions, which is different from verifying a user's identity at login.
- D. Authorization determines what an authenticated user can do, not how they prove who they are.
Authentication
The process of verifying the identity of a user, process, or device before granting access to a system or resource.
- Proves 'who you are'.
- Often relies on something you know, have, or are.
- Precedes authorization.
Memory trick: AAA: Authenticate first, Authorize next, then Audit.