nerdexam
Microsoft

AZ-900 · Question #524

Drag and Drop Question Match the authentication method to the appropriate level of security. To answer, drag the appropriate authentication method from the column on the left to its level of security

The correct answer is Multifactor authentication (MFA) -> High Security, Inconvenient; Passwordless authentication -> High Security, Convenient; Password authentication -> Low Security, Inconvenient. Multifactor authentication (MFA) requires users to provide two or more verification factors (e.g., password + OTP), making it highly secure but less convenient due to additional steps. Passwordless authentication (e.g., biometrics, FIDO2 keys) achieves high security without the b

Submitted by klara.se· Mar 5, 2026Identity, Access, and Authentication Security - understanding the security trade-offs and usability characteristics of different authentication mechanisms (commonly tested in CompTIA Security+, Microsoft SC-900, or AWS Security Specialty certifications)

Question

Drag and Drop Question Match the authentication method to the appropriate level of security. To answer, drag the appropriate authentication method from the column on the left to its level of security on the right. NOTE: Each correct match is worth one point. Answer:

Exhibits

AZ-900 question #524 exhibit 1
AZ-900 question #524 exhibit 2

Answer Area

Drag items

Multifactor authentication (MFA)Password authenticationPasswordless authentication

Correct arrangement

  • Multifactor authentication (MFA) -> High Security, Inconvenient
  • Passwordless authentication -> High Security, Convenient
  • Password authentication -> Low Security, Inconvenient

Explanation

Multifactor authentication (MFA) requires users to provide two or more verification factors (e.g., password + OTP), making it highly secure but less convenient due to additional steps. Passwordless authentication (e.g., biometrics, FIDO2 keys) achieves high security without the burden of remembering passwords, making it both secure AND convenient. Traditional password authentication ranks as low security because passwords are susceptible to phishing, brute force, and credential stuffing attacks, and inconvenient because users must remember and manage complex credentials.

Topics

#Authentication Methods#Identity and Access Management#Security Fundamentals#Zero Trust

Community Discussion

No community discussion yet for this question.

Full AZ-900 Practice