
EC-CouncilNetwork Defense Essentials
Domain 1Objective 5
Authentication Mechanisms and Authorization Systems NDE Practice Questions (Page 6)
Part of the Network Security Fundamentals and Access Control domain, which makes up ~14% of our current practice bank.
47questions here
10free pages
7concepts
Questions 26–30
- 26
An enterprise is implementing SSO across hundreds of applications. The security team is evaluating SAML 2.0 and OIDC. The applications include both legacy on-premises web apps and modern cloud-native apps. The team wants a single protocol that works for both, but they are concerned about the complexity of managing multiple protocols. What is the best recommendation?
Select an answer first - 27
An organization wants to implement multi-factor authentication for its VPN. They currently use a username and password. Which additional factor would be considered 'something you have'?
Select an answer first - 28
A company wants to implement a passwordless authentication method that relies on a cryptographic key pair stored on the user's device. Which authentication mechanism should they choose?
Select an answer first - 29
A company wants to strengthen authentication for remote employees accessing the HR portal. Currently, employees log in with a username and password. The security team wants to add a second factor that is resistant to phishing and does not require employees to carry a separate hardware device. Which solution best meets these requirements?
Select an answer first - 30
Why is multi-factor authentication (MFA) considered more secure than single-factor authentication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.