Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

A financial institution needs to secure access to its core banking applications. They want to ensure that even if an attacker gains access to a user's password, they still cannot access the system without a second verification step, such as a code from a mobile app or a biometric scan. Which identity security control is being described?

  1. ADirectory Synchronization
  2. BSingle Sign-On (SSO)
  3. CMulti-Factor Authentication (MFA)
  4. DPasswordless Authentication
Show answer & explanation

Correct answer: C. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to provide two or more distinct verification factors to gain access, significantly enhancing security by making it harder for attackers to compromise accounts.

Why the other options are wrong

  • A. Directory Synchronization synchronizes identity data between directories, not an authentication method.
  • B. SSO allows users to log in once and access multiple applications, not primarily focused on requiring multiple factors for the initial login.
  • D. Passwordless authentication removes the need for a password, but still typically uses multiple factors.

Multi-Factor Authentication (MFA)

A security system that requires more than one method of authentication from independent categories of credentials to verify the user's identity.

  • Combines 'something you know', 'something you have', 'something you are'.
  • Significantly increases account security.
  • A key component of Zero Trust frameworks.

Memory trick: MFA adds a second layer of security.

More Describe the concepts of security, compliance, and identity questions