Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A company requires that employees accessing highly sensitive financial data must not only provide their username and password but also use a mobile authenticator app to generate a one-time code. This policy applies regardless of the employee's location or device. Which security measure is being enforced?
- ASingle Sign-On (SSO)
- BConditional Access
- CRole-Based Access Control (RBAC)
- DMulti-Factor Authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: D. Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) requires users to provide two or more verification factors to gain access to a resource, typically 'something you know' (password) and 'something you have' (authenticator app), significantly increasing security.
Why the other options are wrong
- A. SSO simplifies logins across multiple systems but doesn't inherently add extra factors.
- B. Conditional Access is a policy engine that could enforce MFA, but MFA is the security measure itself being enforced.
- C. RBAC assigns permissions based on job roles, not additional authentication factors.
Multi-Factor Authentication (MFA)
A security system that requires a user to provide two or more distinct forms of authentication before being granted access to a system or application.
- Combines different types of authentication factors (e.g., knowledge, possession, inherence).
- Significantly reduces the risk of unauthorized access.
- Often a strong recommendation or requirement for sensitive data.
Memory trick: MFA: Two keys are better than one.