Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

A company allows staff to log in to its network only after entering a password and then a one-time code sent to their registered mobile phone. Which security principle does this control apply?

The control is multi-factor authentication. It combines something the user knows, the password, with something the user has, the phone receiving the one-time code. Two independent categories of proof make unauthorised access harder than a password alone, unlike single sign-on or packet filtering.

  1. ASingle sign-on using one credential for all systems
  2. BMulti-factor authentication combining two different categories of proofCorrect
  3. CRole-based encryption of stored files
  4. DPacket filtering at the network boundary

Explanation

A password is something the user knows and an OTP to a phone is something the user has, so two different factor categories are combined. Single sign-on reduces the number of logins, not the factors. Packet filtering and file encryption are different controls.

Did you get it right without looking?

One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.

More Network Basics and Security questions