HomeSubjectsUniversityBlogAbout

Authentication & Access Control

Topic in Cyber Security

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Authentication verifies who a user is, while access control decides what that verified identity is allowed to do with each resource. Questions cover the factor types (something you know, have or are), multi-factor authentication, one-time passwords such as TOTP and HOTP, hardware keys using FIDO2, and biometric error rates like FAR and FRR. Protocol items compare Kerberos, RADIUS and TACACS+, and SAML with OAuth 2.0 and OpenID Connect, including the risks of unbound bearer tokens. You should also know password salting and hashing, pass-the-hash attacks, single sign-on, and access control models such as DAC, MAC, RBAC and ABAC.

Below are 30 practice questions from a pool of 210 Authentication & Access Control MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Authentication & Access ControlEasy

Q1. What are the three main factors of authentication?

  1. A.Name, address, phone within enterprise security environments
  2. B.Hardware, software, firmware within enterprise security environments
  3. C.Username, password, email within enterprise security environments
  4. D.Something you know, something you have, something you are✓ Correct

Explanation

The three factors are: knowledge (something you know), possession (something you have), and inherence (something you are).

Report an error in this question

Authentication & Access ControlEasy

Q2. What is a biometric authentication method?

  1. A.Authenticating identity using a traditional password or passphrase
  2. B.Using physical characteristics like fingerprints or facial recognition to verify identity✓ Correct
  3. C.Using a smart card hardware token for two-factor authentication
  4. D.Using a numeric PIN code for verifying user identity at login

Explanation

Biometric authentication uses unique physical or behavioral characteristics for identity verification.

Report an error in this question

Authentication & Access ControlEasy

Q3. What is multi-factor authentication (MFA)?

  1. A.Using multiple different passwords for one account
  2. B.Using two or more different verification methods to confirm identity✓ Correct
  3. C.Displaying multiple login screens for a single service
  4. D.Using multiple different usernames for one account

Explanation

MFA requires two or more independent verification factors to authenticate a user.

Report an error in this question

Authentication & Access ControlEasy

Q4. What is the purpose of a username?

  1. A.To speed up computer processing performance speed
  2. B.To identify a specific user account in a system✓ Correct
  3. C.To create automated backup copies of user data
  4. D.To encrypt data using symmetric cipher algorithms

Explanation

A username serves as a unique identifier for a user account during the identification phase.

Report an error in this question

Authentication & Access ControlEasy

Q5. What is role-based access control (RBAC)?

  1. A.Access permissions assigned based on a user's role within the organization✓ Correct
  2. B.No formal access control mechanism exists in the system
  3. C.Everyone has the same unrestricted access to resources
  4. D.Access is assigned randomly without specific criteria

Explanation

RBAC assigns permissions to organizational roles rather than individual users.

Report an error in this question

Authentication & Access ControlEasy

Q6. What is a PIN (Personal Identification Number)?

  1. A.A numeric password used to authenticate a user's identity✓ Correct
  2. B.A symmetric key data encryption algorithm
  3. C.A network identifier assigned to connected devices
  4. D.A physical metal pin used for hardware components

Explanation

A PIN is a short numeric code used as a knowledge-based authentication factor.

Report an error in this question

Authentication & Access ControlEasy

Q7. What is a one-time password (OTP)?

  1. A.A shared password used by multiple user accounts
  2. B.A permanent password that never expires or changes
  3. C.A password valid for only one login session or transaction✓ Correct
  4. D.A master password that unlocks all system accounts

Explanation

An OTP is valid for only one authentication session, providing additional security.

Report an error in this question

Authentication & Access ControlEasy

Q8. What is authorization?

  1. A.Permanently deleting files and data from the system storage drives
  2. B.Determining what resources and actions an authenticated user is allowed to access✓ Correct
  3. C.Creating and provisioning a new user account entry in the directory
  4. D.Verifying and confirming who you are as a user during the login process

Explanation

Authorization determines what permissions and access rights an authenticated user has.

Report an error in this question

Authentication & Access ControlEasy

Q9. What is account lockout?

  1. A.Normally logging out of an active and authenticated user session
  2. B.A security mechanism that locks an account after too many failed login attempts✓ Correct
  3. C.Permanently deleting and removing a user account from the system
  4. D.Changing a user account password for improved security posture

Explanation

Account lockout disables an account after too many failed attempts, protecting against brute-force attacks.

Report an error in this question

Authentication & Access ControlEasy

Q10. What is single sign-on (SSO)?

  1. A.An authentication scheme allowing a user to log in once and access multiple systems✓ Correct
  2. B.A next-generation firewall for filtering network traffic flows
  3. C.Creating a single user account for system administration
  4. D.Using one password for everything without variation

Explanation

SSO allows users to authenticate once and access multiple independent systems without re-authenticating.

Report an error in this question

Authentication & Access ControlMedium

Q11. What is privilege escalation?

  1. A.Installing new software applications on the system
  2. B.Gaining elevated access rights beyond what was initially authorized✓ Correct
  3. C.Receiving a job promotion or advancement opportunity
  4. D.Creating a new user account with default permissions

Explanation

Privilege escalation occurs when a user gains higher access rights than intended.

Report an error in this question

Authentication & Access ControlMedium

Q12. What is the difference between authentication and authorization?

  1. A.Neither process is used in modern security frameworks
  2. B.Authentication verifies identity, authorization determines permissions✓ Correct
  3. C.Authorization always comes before the authentication phase
  4. D.They are functionally identical frameworks with no differences

Explanation

Authentication confirms identity through credentials, while authorization determines permitted access.

Report an error in this question

Authentication & Access ControlMedium

Q13. What is a federated identity?

  1. A.A physical security measure for protecting building infrastructure
  2. B.A fake identity created for fraudulent purposes used in enterprise computing environments
  3. C.A temporary identity assigned for a single session used in enterprise computing environments
  4. D.A system allowing users to use the same identity credentials across multiple organizations✓ Correct

Explanation

Federated identity links user identity across multiple security domains for cross-organization access.

Report an error in this question

Authentication & Access ControlMedium

Q14. What is the purpose of a RADIUS server?

  1. A.To provide centralized authentication, authorization, and accounting for network access✓ Correct
  2. B.To measure and calculate distances between network nodes and management
  3. C.To increase and optimize overall network throughput speed
  4. D.To create and deploy enterprise wireless network infrastructure

Explanation

RADIUS provides centralized AAA management for users connecting to network services.

Report an error in this question

Authentication & Access ControlMedium

Q15. What is LDAP used for in access control?

  1. A.A file format used for structured data storage for managing enterprise data resources
  2. B.A high-level language used for development within modern computing environments
  3. C.A software application used for enterprise computing operations
  4. D.A protocol for accessing distributed directory information services for centralized authentication✓ Correct

Explanation

LDAP is used to access centralized directory services that store user credentials for authentication.

Report an error in this question

Authentication & Access ControlMedium

Q16. What is attribute-based access control (ABAC)?

  1. A.Access control decisions based solely on user age and demographics
  2. B.Access control evaluating attributes of users, resources, actions, and environment✓ Correct
  3. C.Randomized access control without any defined criteria or policies
  4. D.Access control based on file system attributes exclusively without context

Explanation

ABAC evaluates rules against attributes of users, resources, actions, and environment for access decisions.

Report an error in this question

Authentication & Access ControlHard

Q17. What is Kerberos authentication protocol?

  1. A.A software application used for enterprise computing operations
  2. B.A ticket-based network authentication protocol using symmetric key cryptography and a trusted third party✓ Correct
  3. C.A standard web browser for accessing internet sites within modern computing environments
  4. D.A standard network communication protocol for data transmission

Explanation

Kerberos uses a Key Distribution Center to issue time-limited tickets for authentication without transmitting passwords.

Report an error in this question

Authentication & Access ControlMedium

Q18. What is the purpose of access control matrices?

  1. A.To define access rights of subjects to objects in a structured format✓ Correct
  2. B.To encrypt data using symmetric cipher algorithms
  3. C.To compress files for reducing disk storage consumption
  4. D.To create and format data management spreadsheets

Explanation

An access control matrix defines what operations each subject can perform on each resource.

Report an error in this question

Authentication & Access ControlHard

Q19. What is the difference between RBAC and ABAC in scalability?

  1. A.Neither is scalable within enterprise security environments
  2. B.RBAC is always more scalable regardless of the specific situation or context
  3. C.ABAC is more scalable for complex environments as it uses attributes rather than requiring new roles✓ Correct
  4. D.They scale identically with no meaningful distinction between them

Explanation

ABAC scales better in complex environments, avoiding the role explosion problem of RBAC.

Report an error in this question

Authentication & Access ControlMedium

Q20. What is the purpose of session management in authentication?

  1. A.To schedule tasks within enterprise computing infrastructure
  2. B.To securely maintain a user's authenticated state throughout their interaction✓ Correct
  3. C.To manage network sessions across the enterprise network infrastructure
  4. D.To manage computer memory within enterprise computing infrastructure

Explanation

Session management maintains authenticated state using tokens while ensuring sessions expire securely.

Report an error in this question

Authentication & Access ControlMedium

Q21. What is SAML (Security Assertion Markup Language)?

  1. A.A high-level language used for development within modern computing environments
  2. B.A software application used for enterprise computing operations
  3. C.An XML-based standard for exchanging authentication and authorization data between providers✓ Correct
  4. D.A database management system for storing structured records

Explanation

SAML allows identity providers to pass authentication credentials to service providers for SSO.

Report an error in this question

Authentication & Access ControlMedium

Q22. What is adaptive authentication?

  1. A.A biometric method within enterprise computing environments
  2. B.An approach adjusting security requirements based on risk factors like location and behavior✓ Correct
  3. C.A credential management mechanism for user authentication flows
  4. D.Fixed authentication rules within enterprise security environments

Explanation

Adaptive authentication dynamically adjusts requirements based on contextual risk factors.

Report an error in this question

Authentication & Access ControlHard

Q23. What is continuous authentication?

  1. A.Logging into the system repeatedly at regular intervals across computing environments
  2. B.A type of multi-factor authentication using OTP tokens used in enterprise computing environments
  3. C.Continuously verifying identity throughout a session using behavioral biometrics and contextual signals✓ Correct
  4. D.A session timeout feature that logs users out within the identity management system

Explanation

Continuous authentication monitors user behavior throughout a session to ensure the authenticated user is still present.

Report an error in this question

Authentication & Access ControlHard

Q24. What is the OAuth 2.0 authorization code flow?

  1. A.A flow where the client receives an authorization code exchanged for tokens via a back-channel✓ Correct
  2. B.A file transfer process within enterprise computing environments
  3. C.A simple password exchange within the identity management system
  4. D.A database query method for managing enterprise data resources

Explanation

The authorization code flow uses a secure back-channel to exchange codes for tokens, keeping tokens out of the browser.

Report an error in this question

Authentication & Access ControlHard

Q25. What is just-in-time (JIT) access provisioning?

  1. A.A type of SSO used across multiple services within enterprise computing environments
  2. B.Permanent access granted for all users regardless of the specific situation or context
  3. C.Fast login systems used for authentication within enterprise security environments
  4. D.Granting privileged access only when needed for a specific duration, then automatically revoking it✓ Correct

Explanation

JIT access grants elevated privileges only when needed and automatically revokes them afterward.

Report an error in this question

Authentication & Access ControlHard

Q26. What is the purpose of Privileged Access Management (PAM)?

  1. A.To create user accounts for enterprise computing environments
  2. B.To manage email accounts within enterprise computing infrastructure
  3. C.To secure, manage, and monitor privileged accounts and access to critical systems✓ Correct
  4. D.To design websites for enterprise computing environments and management

Explanation

PAM solutions manage and audit privileged access including credential vaulting and session recording.

Report an error in this question

Authentication & Access ControlHard

Q27. What is claim-based identity?

  1. A.A type of insurance policy covering liability damages used in enterprise computing environments
  2. B.Using assertions about a user made by a trusted identity provider for authentication and authorization✓ Correct
  3. C.A file management system for organizing stored documents used in enterprise computing environments
  4. D.Filing legal claims in a court of law or tribunal within enterprise security environments

Explanation

Claim-based identity uses assertions issued by trusted providers about user attributes for access decisions.

Report an error in this question

Authentication & Access ControlHard

Q28. What is certificate-based authentication?

  1. A.A training certification program for development used in enterprise computing environments
  2. B.Using digital certificates (X.509) to verify identity, preferred for machine-to-machine communication✓ Correct
  3. C.A structured file format used for data storage and exchange
  4. D.Using paper certificates for physical identity verification

Explanation

Certificate-based authentication uses X.509 digital certificates for identity verification in high-security environments.

Report an error in this question

Authentication & Access ControlHard

Q29. What is the FIDO2 authentication standard?

  1. A.A passwordless authentication standard using public-key cryptography with hardware authenticators✓ Correct
  2. B.A standard network communication protocol for data transmission
  3. C.A credential management mechanism for user authentication flows
  4. D.A file format used for structured data storage for managing enterprise data resources

Explanation

FIDO2 enables passwordless authentication using public-key cryptography with hardware authenticators.

Report an error in this question

Authentication & Access ControlHard

Q30. What is a pass-the-hash attack?

  1. A.A hashing algorithm used for data integrity within enterprise computing environments
  2. B.Sharing passwords openly across teams within enterprise security environments for access
  3. C.A credential management mechanism designed for enterprise user authentication flows
  4. D.An attack where captured password hashes are used directly to authenticate without knowing the password✓ Correct

Explanation

Pass-the-hash uses captured hashes directly to authenticate without cracking the actual password.

Report an error in this question

Ready to test yourself on Authentication & Access Control?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Authentication & Access Control Quiz