Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A cybersecurity team is evaluating different methods for authenticating users to a critical internal application. They want to implement a solution that provides a very high level of assurance by requiring users to present something they know (e.g., password), something they have (e.g., security token), and something they are (e.g., fingerprint). Which authentication method are they planning to deploy?

  1. ASingle Sign-On (SSO)
  2. BBiometric Authentication
  3. CMulti-Factor Authentication (MFA)
  4. DKnowledge-Based Authentication (KBA)
Show answer & explanation

Correct answer: C. Multi-Factor Authentication (MFA)

The scenario describes requiring factors from three distinct categories: knowledge (password), possession (token), and inherence (fingerprint). This combination is known as Multi-Factor Authentication (MFA), specifically requiring three factors.

Why the other options are wrong

  • A. SSO allows access to multiple applications with one login but doesn't define the number or type of factors.
  • B. Biometric authentication is 'something you are' but is only one factor, not the combination described.
  • D. KBA relies solely on 'something you know' (e.g., security questions) and is less secure.

Multi-Factor Authentication (MFA)

An authentication method that requires a user to provide two or more verification factors to gain access to a resource, often categorized as something you know, something you have, and something you are.

  • Significantly improves security over single-factor authentication.
  • Combines different types of authentication factors.
  • Commonly used to protect sensitive accounts.

Memory trick: The more ways you prove you are you, the safer the door.

More Cybersecurity Fundamentals questions