SC-900 Practice Test 19 Hard Questions

SC-900 Exam Practice Test 19 (Hard) - Authentication Methods Deep-Dive

SC-900 Exam Practice Tests

1 / 15

Which authentication factor category does a password belong to?

2 / 15

Which authentication factor category does a physical FIDO2 security key or a smart card belong to?

3 / 15

Which authentication factor category does a fingerprint or facial recognition scan belong to?

4 / 15

Why does combining a password with a code from an authenticator app provide stronger security than a password alone?

5 / 15

Which Microsoft Authenticator app capability allows a user to approve or deny a sign-in attempt with a simple tap, rather than manually typing a numeric code?

6 / 15

Which authentication method is generally considered LESS secure than app-based push notifications or FIDO2 keys, due to vulnerabilities like SIM-swapping attacks?

7 / 15

Which modern authentication credential is a passwordless, phishing-resistant credential based on FIDO standards that can be synced across a user's devices via a platform provider?

8 / 15

Which term describes an authentication method considered resistant to phishing because it does not involve a shared secret, such as a password or one-time code, that could be intercepted or tricked out of a user?

9 / 15

Which term describes the requirement that a specific application or scenario mandates stronger authentication factors before granting access, such as requiring a FIDO2 key for accessing highly sensitive financial systems?

10 / 15

Which certificate-based authentication use case allows an organization to authenticate users based on a digital certificate installed on their device, without relying on a password at all?

11 / 15

Which recommended practice helps reduce the risk of MFA fatigue attacks, where an attacker repeatedly sends push notification prompts hoping a user will eventually approve one by mistake?

12 / 15

Which Conditional Access-related concept combines specific authentication methods together, such as requiring both a password and a compliant device, to satisfy a policy's grant requirements?

13 / 15

Which term describes a scenario where a user is prompted for authentication less frequently on a trusted, previously registered device, improving user experience while maintaining reasonable security?

14 / 15

Which factor combination would be considered TRUE multifactor authentication, as opposed to simply using two credentials from the same factor category?

15 / 15

Which term describes the process by which a user proves ownership of a new authentication method, such as a phone number, before it can be used for future sign-ins or password resets?

Your score is

The average score is 0%

0%