During a post-incident review, a financial services company discovers that attackers successfully used stolen username-password pairs obtained from a dark-web dump to log in to several customer accounts. The security architect must recommend a control that forces users to present more than one distinct type of factor-such as something they know and something they possess-before access is granted. Which solution BEST meets this requirement?
Require quarterly password rotations with strict lockout thresholds
Implement SAML-based single sign-on to consolidate credentials
Deploy multi-factor authentication for all user logins
Enforce a 15-character password complexity and history policy
Deploying multi-factor authentication (MFA) requires users to supply at least two independent factors, such as a password (knowledge) and a one-time code generated by a mobile token (possession). Because an attacker who has only the stolen password still lacks the second factor, MFA is highly effective against credential-stuffing and similar replay attacks. Single sign-on, longer passwords, or frequent rotations still rely on a single factor and do not add the second barrier needed to defeat such attacks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of multi-factor authentication (MFA)?
Open an interactive chat with Bash
How is MFA different from Single Sign-On (SSO)?
Open an interactive chat with Bash
What are common examples of MFA factors?
Open an interactive chat with Bash
ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .