An employee uses a password and a one-time code from a mobile authenticator app to log in. Which authentication type is being used?
Trap 1: Possession-based
Possession-based would be only the OTP.
Trap 2: Biometric
Biometric is a single factor (inherence).
Trap 3: Single-factor
Single-factor uses only one type.
- A
Possession-based
Why it fails: Possession-based would be only the OTP.
- B
Biometric
Why it fails: Biometric is a single factor (inherence).
- C
Single-factor
Why it fails: Single-factor uses only one type.
- D
Multi-factor
Combining a password (something the user knows) with a one-time code from an authenticator app (something the user possesses) satisfies multi-factor authentication, which demands two or more distinct credential categories. Microsoft Entra ID classifies this as multi-factor, meeting the stem's requirement that both a password and a mobile-generated code are presented.