SY0-301 · Question #207
A company with a US-based sales force has requested that the VPN system be configured to authenticate the sales team based on their username, password and a client side certificate. Additionally…
The correct answer is C. 3. The VPN uses three distinct authentication factors: something you know (username and password together), something you have (client-side certificate), and somewhere you are (US geographic restriction).
Question
A company with a US-based sales force has requested that the VPN system be configured to authenticate the sales team based on their username, password and a client side certificate. Additionally, the security administrator has restricted the VPN to only allow authentication from the US territory. How many authentication factors are in use by the VPN system?
Options
- A1
- B2
- C3
- D4
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C72% (21)
- D17% (5)
Why each option
The VPN uses three distinct authentication factors: something you know (username and password together), something you have (client-side certificate), and somewhere you are (US geographic restriction).
One factor would mean only a single authentication category is used, but the scenario clearly combines knowledge, possession, and location factors.
Two factors would account for only knowledge and possession, omitting the geographic location restriction which constitutes a separate 'somewhere you are' factor.
Authentication factors are categorized by type, not by the number of credentials. Username and password together constitute one factor type (something you know), the client-side certificate is a second factor (something you have), and the geographic restriction to the US territory is a third factor (somewhere you are), yielding three total authentication factors.
Four factors would require an additional category such as something you are (biometrics), which is not present in this scenario.
Concept tested: Multi-factor authentication factor counting and categorization
Source: https://pages.nist.gov/800-63-3/sp800-63b.html
Topics
Community Discussion
No community discussion yet for this question.