A Check Point administrator is configuring user authentication for a Remote Access VPN. The administrator wants to use certificates for authentication but also requires a second factor. The administrator decides to use SecurID tokens as the second factor. Which authentication method should be configured in the user object to achieve this?
The authentication method 'Certificate + SecurID' is a multi-factor authentication option in Check Point that requires both a valid client certificate and a SecurID token code. This precisely matches the administrator's requirement to use certificates as the primary factor and SecurID as the second factor for Remote Access VPN authentication.
Why this answer
To use certificates and SecurID tokens together, the user object must be configured with the 'Certificate + SecurID' authentication method. This method enforces both factors: the user must present a valid certificate and a correct SecurID token code. Other methods either use only one factor or substitute the certificate with a password.
Exam trap
The trap here is selecting 'SecurID' alone or 'Certificate' alone, missing the requirement for multi-factor authentication combining both.