SSCP Systems Security Certified PractitionerAccess ControlsEasy
A financial institution is implementing a new customer authentication system. They require customers to enter a username and password, then receive a one-time passcode (OTP) via a registered mobile device, and finally, answer a security question from a pre-defined list. This combination satisfies which authentication concept?
- ASingle Sign-On (SSO)
- BDiscretionary Access Control (DAC)
- CMulti-Factor Authentication (MFA)
- DFederated Identity Management
Show answer & explanationAnswer & explanation
Correct answer: C. Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) requires a user to provide two or more distinct types of credentials from different categories of factors to verify their identity. In this scenario, the user provides something they know (password and security question) and something they have (mobile device for OTP), fulfilling the MFA requirement.
Why the other options are wrong
- A. SSO allows a single login to access multiple systems, which is not described here.
- B. DAC is an access control model where resource owners define permissions, not an authentication method.
- D. Federated Identity Management enables identity exchange across different security domains, not the authentication process itself.
Multi-Factor Authentication (MFA)
An authentication method that requires the user to present two or more verification factors from independent categories.
- Enhances security by requiring more than one proof of identity.
- Factors include knowledge (something you know), possession (something you have), and inherence (something you are).
- Reduces the risk of unauthorized access even if one factor is compromised.
Memory trick: More factors mean more fortress security.