156-215.80 · Question #293
Which the following type of authentication on Mobile Access can NOT be used as the first authentication method?
The correct answer is A. Dynamic ID. Dynamic ID (one-time password) cannot serve as the first authentication factor in Check Point Mobile Access because it depends on a prior identity being established to deliver the OTP.
Question
Which the following type of authentication on Mobile Access can NOT be used as the first authentication method?
Options
- ADynamic ID
- BRADIUS
- CUsername and Password
- DCertificate
How the community answered
(29 responses)- A90% (26)
- B7% (2)
- C3% (1)
Why each option
Dynamic ID (one-time password) cannot serve as the first authentication factor in Check Point Mobile Access because it depends on a prior identity being established to deliver the OTP.
Dynamic ID generates a one-time password that must be delivered to a user who has already been partially identified, making it inherently a second-factor mechanism. Check Point Mobile Access requires the first authentication method to independently verify identity, which OTP alone cannot do. Therefore Dynamic ID is restricted to use as a subsequent factor only.
RADIUS is a supported first authentication method in Mobile Access because it can independently verify credentials against a RADIUS server.
Username and Password is the most common first authentication method and is fully supported as an initial factor in Mobile Access.
Certificate-based authentication is a valid first authentication method because the certificate itself establishes user identity without requiring a prior step.
Concept tested: Mobile Access first-factor authentication method restrictions
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_MobileAccess_AdminGuide/Content/Topics-MAAG/Authentication-Schemes.htm
Topics
Community Discussion
No community discussion yet for this question.