nerdexam
CompTIA

CAS-003 · Question #51

An insurance company has two million customers and is researching the top transactions on its customer portal. It identifies that the top transaction is currently password reset. Due to users not…

The correct answer is C. SMS with OTP sent to a mobile number E. Certificate sent to be installed on a device. The requirements are: single-factor authentication, passwordless, mobile-focused, minimal management overhead, and elimination of contact center calls. SMS with OTP (C) is passwordless, single-factor, and tied to the customer's mobile number - it eliminates the need for secret…

Technical Integration of Enterprise Security

Question

An insurance company has two million customers and is researching the top transactions on its customer portal. It identifies that the top transaction is currently password reset. Due to users not remembering their secret questions, a large number of calls are consequently routed to the contact center for manual password resets. The business wants to develop a mobile application to improve customer engagement in the future, continue with a single factor of authentication, minimize management overhead of the solution, remove passwords, and eliminate to the contact center. Which of the following techniques would BEST meet the requirements? (Choose two.)

Options

  • AMagic link sent to an email address
  • BCustomer ID sent via push notification
  • CSMS with OTP sent to a mobile number
  • DThird-party social login
  • ECertificate sent to be installed on a device
  • FHardware tokens sent to customers

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    47% (15)
  • D
    28% (9)
  • F
    16% (5)

Explanation

The requirements are: single-factor authentication, passwordless, mobile-focused, minimal management overhead, and elimination of contact center calls. SMS with OTP (C) is passwordless, single-factor, and tied to the customer's mobile number - it eliminates the need for secret questions and reduces contact center volume. A certificate installed on the mobile device (E) is also passwordless and single-factor; once provisioned, it authenticates silently without user input, eliminating further contact center friction. Magic links (A) require email access, adding complexity. Push notifications with customer ID (B) are not standard authentication. Social login (D) introduces third-party dependency and doesn't remove password reuse risk. Hardware tokens (F) are expensive to distribute to two million customers and increase, not minimize, overhead.

Topics

#authentication#mobile security#passwordless#PKI certificates

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice