
EC-CouncilCertified Security Specialist
Domain 1Objective 2
Identification, Authentication, and Authorization ECSS Practice Questions (Page 1)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
46questions here
10free pages
9concepts
Questions 1–5
- 1
A security analyst is reviewing the login process for a high-security research facility. The system first asks the user to present a badge that contains a unique employee ID. The system then verifies the employee's fingerprint. In this process, what is the employee ID serving as?
Select an answer first - 2
A company is deploying MFA for all employees. The security team wants to minimize the risk of phishing and SIM-swapping attacks, but also wants to keep costs low and avoid issuing physical hardware to hundreds of employees. Which MFA method best balances these constraints?
Select an answer first - 3
A healthcare organization is implementing a new authentication system for its electronic health record (EHR) platform. The security team wants to use a biometric factor as the primary authentication method. Which of the following would qualify as a biometric factor?
Select an answer first - 4
A user attempts to log in to a corporate workstation. The system prompts for a username and then a password. After entering both, the user is granted access to the desktop. Which sequence of security processes has occurred?
Select an answer first - 5
A company is implementing MFA for remote access. The security team is considering two options: Option 1 requires a password and a one-time code from an authenticator app. Option 2 requires a password and a fingerprint scan. The company's policy states that MFA must use two different authentication factors. Which option(s) satisfy this policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.