SSCP Systems Security Certified PractitionerAccess ControlsEasy
A company requires its employees to use a physical smart card containing a digital certificate, along with a personal identification number (PIN), to log in to their workstations. This system aims to enhance security beyond a simple password. Which of the following authentication methods is being employed?
- AMulti-Factor Authentication (MFA)
- BSomething You Have
- CSomething You Are
- DSomething You Know
Show answer & explanationAnswer & explanation
Correct answer: A. Multi-Factor Authentication (MFA)
The scenario requires both 'something you have' (the smart card) and 'something you know' (the PIN). When two or more distinct authentication factors are used, it constitutes Multi-Factor Authentication (MFA).
Why the other options are wrong
- B. This refers only to the smart card, ignoring the PIN.
- C. This refers to biometrics, which are not mentioned in the scenario.
- D. This refers only to the PIN, ignoring the smart card.
Multi-Factor Authentication (MFA)
An authentication method that requires a user to provide two or more verification factors to gain access to a resource.
- Combines different types of factors (knowledge, possession, inherence).
- Significantly increases security by making it harder for attackers to gain access.
- Common examples include username/password + OTP, smart card + PIN.
Memory trick: MFA is like a security combo lock, needing multiple different types of inputs.