
EC-CouncilCertified Security Specialist
Domain 1Objective 2
Identification, Authentication, and Authorization ECSS Practice Questions (Page 8)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
46questions here
10free pages
9concepts
Questions 36–40
- 36
Why is Multi-Factor Authentication (MFA) considered more secure than using a single password?
Select an answer first - 37
A bank is deploying a new online banking platform. The security team requires that customers authenticate using their password and a one-time code generated by a hardware token. The bank also wants to add a third factor by requiring a fingerprint scan on the customer's mobile device. How many distinct authentication factors will be used in total?
Select an answer first - 38
A user logs into a system by entering the username 'jsmith' and then the correct password. After login, the system checks whether 'jsmith' has permission to access the payroll folder. Which sequence of processes is occurring?
Select an answer first - 39
A government agency classifies documents as 'Confidential' or 'Top Secret'. Users are granted security clearances, and the system automatically prevents a user with a 'Confidential' clearance from reading 'Top Secret' documents. Which authorization model is being enforced?
Select an answer first - 40
A financial services firm wants to strengthen remote access for its administrators. Currently, administrators log in with a username and password. The firm wants to require a second factor that is not easily phished. Which option best meets this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.