nerdexam
CompTIA

SY0-301 · Question #207

A company with a US-based sales force has requested that the VPN system be configured to authenticate the sales team based on their username, password and a client side certificate. Additionally…

The correct answer is C. 3. The VPN uses three distinct authentication factors: something you know (username and password together), something you have (client-side certificate), and somewhere you are (US geographic restriction).

General security concepts

Question

A company with a US-based sales force has requested that the VPN system be configured to authenticate the sales team based on their username, password and a client side certificate. Additionally, the security administrator has restricted the VPN to only allow authentication from the US territory. How many authentication factors are in use by the VPN system?

Options

  • A1
  • B2
  • C3
  • D4

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    72% (21)
  • D
    17% (5)

Why each option

The VPN uses three distinct authentication factors: something you know (username and password together), something you have (client-side certificate), and somewhere you are (US geographic restriction).

A1

One factor would mean only a single authentication category is used, but the scenario clearly combines knowledge, possession, and location factors.

B2

Two factors would account for only knowledge and possession, omitting the geographic location restriction which constitutes a separate 'somewhere you are' factor.

C3Correct

Authentication factors are categorized by type, not by the number of credentials. Username and password together constitute one factor type (something you know), the client-side certificate is a second factor (something you have), and the geographic restriction to the US territory is a third factor (somewhere you are), yielding three total authentication factors.

D4

Four factors would require an additional category such as something you are (biometrics), which is not present in this scenario.

Concept tested: Multi-factor authentication factor counting and categorization

Source: https://pages.nist.gov/800-63-3/sp800-63b.html

Topics

#multi-factor authentication#VPN authentication#certificate-based auth#authentication factors

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice