An organization requires users to authenticate with a password and a one-time code sent to their mobile phone. This is an example of which authentication method?
Trap 1: Two-step verification
Two-step verification (2SV) involves a second authentication step, but it does not inherently guarantee the use of a different authentication factor type. For instance, it could involve a password followed by security questions, both relying on "something you know." While often implemented with different factors, 2SV's definition is broader and doesn't strictly meet the security requirement of combining distinct factor types for enhanced assurance, which is the hallmark of true multi-factor authentication.
Trap 2: Single-factor authentication
Single-factor authentication (SFA) relies on only one category of authentication credential, such as solely a password ("something you know") or a smart card ("something you have"). This method is inherently less secure as compromise of that single factor grants full access. The question implies a need for a more robust authentication mechanism than just a password, making SFA an insufficient security control against modern threats like phishing or credential stuffing.
Trap 3: Step-up authentication
Step-up authentication is a dynamic security measure where additional authentication factors are requested only when a user attempts to access more sensitive resources or perform high-risk transactions *after* an initial login. The scenario describes a general organizational requirement for user authentication at the standard login stage, not a conditional enhancement for specific, elevated operations. Therefore, it doesn't address the baseline authentication need.
- A
Two-step verification
Why it fails: Two-step verification (2SV) involves a second authentication step, but it does not inherently guarantee the use of a different authentication factor type. For instance, it could involve a password followed by security questions, both relying on "something you know." While often implemented with different factors, 2SV's definition is broader and doesn't strictly meet the security requirement of combining distinct factor types for enhanced assurance, which is the hallmark of true multi-factor authentication.
- B
Single-factor authentication
Why it fails: Single-factor authentication (SFA) relies on only one category of authentication credential, such as solely a password ("something you know") or a smart card ("something you have"). This method is inherently less secure as compromise of that single factor grants full access. The question implies a need for a more robust authentication mechanism than just a password, making SFA an insufficient security control against modern threats like phishing or credential stuffing.
- C
Step-up authentication
Why it fails: Step-up authentication is a dynamic security measure where additional authentication factors are requested only when a user attempts to access more sensitive resources or perform high-risk transactions *after* an initial login. The scenario describes a general organizational requirement for user authentication at the standard login stage, not a conditional enhancement for specific, elevated operations. Therefore, it doesn't address the baseline authentication need.
- D
Multi-factor authentication
Multi-factor authentication (MFA) is the correct choice because it mandates the use of two or more distinct authentication factor types to verify a user's identity. These factors typically include "something you know" (e.g., password), "something you have" (e.g., token, phone), and "something you are" (e.g., fingerprint). By combining different categories, MFA significantly enhances security, making it exponentially harder for unauthorized individuals to gain access even if one factor is compromised.