Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

A global organization is implementing a new security policy that requires all users to provide two different forms of verification before accessing sensitive internal applications. Which security concept is this organization primarily implementing?

  1. ALeast Privilege
  2. BSingle Sign-On (SSO)
  3. CConditional Access
  4. DMulti-Factor Authentication (MFA)
Show answer & explanation

Correct answer: D. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to provide two or more verification factors to gain access to a resource, significantly increasing security by making it harder for unauthorized users to gain access.

Why the other options are wrong

  • A. Least Privilege focuses on granting users only the necessary permissions, not on the number of authentication factors.
  • B. Single Sign-On (SSO) allows users to access multiple applications with one set of credentials, which is different from requiring multiple factors for a single login.
  • C. Conditional Access defines access policies based on conditions, but the core concept of requiring two forms of verification is MFA.

Multi-Factor Authentication (MFA)

A security system that requires users to provide two or more verification factors to gain access to a resource.

  • Enhances security by requiring multiple proofs of identity.
  • Combines different types of authentication factors (e.g., something you know, something you have, something you are).
  • Significantly reduces the risk of unauthorized access.

Memory trick: Many Factors Secure Access

More Describe the concepts of security, compliance, and identity questions