Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A security architect is designing a system that requires users to provide two different forms of authentication, such as a password and a one-time code from a mobile app, before granting access. What security mechanism is being implemented?

  1. ABiometric Authentication
  2. BMulti-Factor Authentication (MFA)
  3. CSingle Sign-On (SSO)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: B. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to present at least two different types of authentication factors to verify their identity, significantly enhancing security.

Why the other options are wrong

  • A. Biometric authentication uses unique physical characteristics (e.g., fingerprint, facial scan) as one factor, which can be part of MFA but is not MFA itself.
  • C. SSO allows users to log in once and gain access to multiple systems without re-authenticating, simplifying access, not necessarily strengthening it with multiple factors.
  • D. RBAC assigns permissions based on a user's role within an organization, controlling *what* they can access, not *how* they authenticate.

Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) is a security system that requires a user to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN.

  • Combines different types of authentication factors.
  • Common factors: knowledge (password), possession (token), inherence (biometrics).
  • Significantly reduces the risk of unauthorized access.

Memory trick: Authentication can be Single, Multi, or Identity-based.

More Cybersecurity Fundamentals questions