nerdexam
CyberArk

ACCESS-DEF · Question #26

As part of compliance regulation, ACME Corporation is enforcing MFA for its critical business web-based application. To increase security and MFA compliance, CyberArk recommends selecting mechanisms…

The correct answer is B. Security Question. Security Question (B) falls under the "Something you know" category because it relies on knowledge only the user possesses - a memorized answer to a personal question. Phone Call (A) and Text Message/SMS (C) both fall under "Something you have," since they require possession of…

Authentication and Authorization

Question

As part of compliance regulation, ACME Corporation is enforcing MFA for its critical business web-based application. To increase security and MFA compliance, CyberArk recommends selecting mechanisms from different categories. Within the authentication policy, ACME Corporation made the requirement to configure an authentication mechanism with "Something you know". Which authentication mechanism meets this requirement?

Options

  • APhone Call
  • BSecurity Question
  • CText Message (SMS) Confirmation Code
  • DFIDO2 Authenticators

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    92% (24)
  • D
    4% (1)

Explanation

Security Question (B) falls under the "Something you know" category because it relies on knowledge only the user possesses - a memorized answer to a personal question. Phone Call (A) and Text Message/SMS (C) both fall under "Something you have," since they require possession of a physical device (your phone) to receive the code. FIDO2 Authenticators (D) typically fall under "Something you have" (a hardware key like a YubiKey) or "Something you are" (biometric), depending on implementation - never "Something you know."

Memory tip: Use the acronym KHA - Know (passwords, PINs, security questions), Have (phone, token, smart card), Are (fingerprint, face, retina). If the factor disappears when you forget it rather than lose it, it's "Something you know."

Topics

#Multi-Factor Authentication#Authentication Factors#Knowledge Factor#MFA Mechanisms

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice