SSCP Systems Security Certified PractitionerAccess ControlsMedium

A financial institution is implementing a new customer authentication system. They require customers to provide something they know (password), something they have (a hardware token), and something they are (fingerprint scan). This approach is designed to achieve which specific security objective?

  1. ANon-repudiation
  2. BAvailability
  3. CAuthentication Strength
  4. DConfidentiality
Show answer & explanation

Correct answer: C. Authentication Strength

Using multiple, distinct authentication factors (something you know, have, and are) significantly increases the difficulty for an unauthorized entity to gain access, thus enhancing the overall authentication strength.

Why the other options are wrong

  • A. Non-repudiation ensures that a party cannot deny having performed an action, which is a different objective than proving identity at login.
  • B. Availability ensures that authorized users can access systems when needed, which is not the primary goal of this multi-factor approach.
  • D. Confidentiality protects information from unauthorized disclosure, but this scenario focuses on proving identity, not data protection directly.

Authentication Strength

The level of assurance that an asserted identity is genuine, determined by the robustness of the authentication factors and methods used.

  • Increased by combining multiple, distinct authentication factors.
  • Reduces the likelihood of unauthorized access.
  • Crucial for protecting sensitive systems and data.

Memory trick: Strong Auth: Know, Have, Are, to be sure!

More Access Controls questions