SSCP Systems Security Certified PractitionerAccess ControlsMedium

A financial institution requires its customers to use a username and password, along with a one-time code sent to their registered mobile device, to access their online banking portal. What type of authentication is being used?

  1. AMulti-factor authentication (MFA)
  2. BBiometric authentication
  3. CFederated authentication
  4. DSingle-factor authentication
Show answer & explanation

Correct answer: A. Multi-factor authentication (MFA)

Multi-factor authentication (MFA) requires a user to present two or more different authentication factors. In this case, 'something you know' (username/password) and 'something you have' (mobile device receiving a one-time code) are used.

Why the other options are wrong

  • B. Biometric authentication uses physical traits (e.g., fingerprint), which is not described here.
  • C. Federated authentication allows SSO across different domains but doesn't specify the number of factors used for initial authentication.
  • D. Single-factor authentication uses only one type of factor (e.g., just a password).

Multi-Factor Authentication (MFA)

An authentication method that requires users to provide two or more distinct verification factors to gain access to a resource.

  • Significantly enhances security over single-factor authentication.
  • Combines different types of factors (knowledge, possession, inherence).
  • Commonly used in sensitive applications like banking.

Memory trick: MFA: Many Factors make it harder to crack.

More Access Controls questions