SSCP Systems Security Certified PractitionerSystems and Application SecurityHard
A security architect is designing a system that requires the highest level of assurance for user identity verification before granting access to sensitive data. The system must confirm the user's identity based on something they know, something they have, and something they are. Which authentication mechanism meets these requirements?
- AMulti-factor authentication (MFA) combining a password and a one-time password (OTP) from a token.
- BThree-factor authentication (3FA) using a password, a smart card, and a fingerprint.
- CBiometric authentication with a fingerprint scanner and a smart card.
- DSingle sign-on (SSO) with a strong password policy.
Show answer & explanationAnswer & explanation
Correct answer: B. Three-factor authentication (3FA) using a password, a smart card, and a fingerprint.
The requirement specifies 'something they know', 'something they have', and 'something they are'. A password (something they know), a smart card (something they have), and a fingerprint (something they are) combine three distinct factors of authentication, which is precisely what 3FA aims to achieve.
Why the other options are wrong
- A. This is two-factor authentication (something you know, something you have).
- C. This combines 'something you have' (smart card) and 'something you are' (fingerprint), but lacks 'something you know'.
- D. SSO simplifies access but doesn't inherently define the number of factors; it often relies on existing authentication mechanisms.
Authentication Factors
Categories of credentials used to verify a user's identity. There are typically three main types: knowledge, possession, and inherence.
- Something you know (e.g., password, PIN).
- Something you have (e.g., smart card, token, phone).
- Something you are (e.g., fingerprint, retina scan, voice).
Memory trick: MFA is like needing multiple keys of different types to open a secure door.