ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A company is implementing a new physical access control system for its data center. The system requires employees to swipe an access card and then provide a fingerprint scan before entry. What type of authentication is being implemented here?

  1. ATwo-factor authorization
  2. BSingle-factor authentication
  3. CMulti-factor authentication (MFA)
  4. DBiometric authentication
Show answer & explanation

Correct answer: C. Multi-factor authentication (MFA)

Multi-factor authentication (MFA) requires two or more independent authentication factors to verify a user's identity. In this scenario, the access card (something you have) and the fingerprint scan (something you are) represent two distinct factors, thus qualifying as MFA.

Why the other options are wrong

  • A. Authorization is about what access is granted, not how identity is verified. 'Two-factor' applies to authentication, not authorization.
  • B. Single-factor authentication uses only one type of credential.
  • D. Biometric authentication is one type of factor ('something you are'), but the scenario includes a second factor (access card), making MFA the best description.

Multi-factor Authentication (MFA)

An authentication method that requires a user to present two or more different authentication factors to verify their identity.

  • Combines different types of factors (e.g., knowledge, possession, inherence)
  • Significantly increases security over single-factor
  • Commonly used for sensitive systems/data

Memory trick: MFA: 'Something you Know, Have, Are' – K.H.A.!

More Access Controls Concepts questions