Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A company requires that employees accessing highly sensitive financial data must not only provide their username and password but also use a mobile authenticator app to generate a one-time code. This policy applies regardless of the employee's location or device. Which security measure is being enforced?

  1. ASingle Sign-On (SSO)
  2. BConditional Access
  3. CRole-Based Access Control (RBAC)
  4. DMulti-Factor Authentication (MFA)
Show answer & explanation

Correct answer: D. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to provide two or more verification factors to gain access to a resource, typically 'something you know' (password) and 'something you have' (authenticator app), significantly increasing security.

Why the other options are wrong

  • A. SSO simplifies logins across multiple systems but doesn't inherently add extra factors.
  • B. Conditional Access is a policy engine that could enforce MFA, but MFA is the security measure itself being enforced.
  • C. RBAC assigns permissions based on job roles, not additional authentication factors.

Multi-Factor Authentication (MFA)

A security system that requires a user to provide two or more distinct forms of authentication before being granted access to a system or application.

  • Combines different types of authentication factors (e.g., knowledge, possession, inherence).
  • Significantly reduces the risk of unauthorized access.
  • Often a strong recommendation or requirement for sensitive data.

Memory trick: MFA: Two keys are better than one.

More Describe the concepts of security, compliance, and identity questions