Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A financial institution requires employees to use a smart card in addition to their password to access sensitive customer data. This practice significantly strengthens the security posture by requiring two distinct types of evidence to verify identity. What term best describes this security measure?

  1. AConditional Access
  2. BMulti-Factor Authentication (MFA)
  3. CSingle Sign-On (SSO)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: B. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires a user to provide two or more verification factors from different categories (e.g., something you know like a password, something you have like a smart card, something you are like a fingerprint) to gain access. The scenario clearly describes using a password (something you know) and a smart card (something you have).

Why the other options are wrong

  • A. Conditional Access defines access policies based on conditions, which can involve MFA but isn't MFA itself.
  • C. SSO allows access to multiple applications with one login, but doesn't inherently require multiple factors.
  • D. RBAC assigns permissions based on job roles, not on the method of identity verification.

Multi-Factor Authentication (MFA)

An authentication method that requires a user to provide two or more verification factors to gain access to a resource.

  • Combines factors from different categories (knowledge, possession, inherence).
  • Significantly enhances security against credential theft.
  • Commonly used in conjunction with passwords.

Memory trick: MFA: More Factors, Fewer Failures.

More Describe the concepts of security, compliance, and identity questions