SSCP Systems Security Certified PractitionerAccess ControlsMedium
A financial institution requires its customers to use a username and password, along with a one-time code sent to their registered mobile device, to access their online banking portal. What type of authentication is being used?
- AMulti-factor authentication (MFA)
- BBiometric authentication
- CFederated authentication
- DSingle-factor authentication
Show answer & explanationAnswer & explanation
Correct answer: A. Multi-factor authentication (MFA)
Multi-factor authentication (MFA) requires a user to present two or more different authentication factors. In this case, 'something you know' (username/password) and 'something you have' (mobile device receiving a one-time code) are used.
Why the other options are wrong
- B. Biometric authentication uses physical traits (e.g., fingerprint), which is not described here.
- C. Federated authentication allows SSO across different domains but doesn't specify the number of factors used for initial authentication.
- D. Single-factor authentication uses only one type of factor (e.g., just a password).
Multi-Factor Authentication (MFA)
An authentication method that requires users to provide two or more distinct verification factors to gain access to a resource.
- Significantly enhances security over single-factor authentication.
- Combines different types of factors (knowledge, possession, inherence).
- Commonly used in sensitive applications like banking.
Memory trick: MFA: Many Factors make it harder to crack.