0% found this document useful (0 votes)
7 views2 pages

Secure Multi-Factor Authentication Methods

Uploaded by

sixthbit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as ODT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views2 pages

Secure Multi-Factor Authentication Methods

Uploaded by

sixthbit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as ODT, PDF, TXT or read online on Scribd

### **Answer Key**

#### *MCQs*

[Link] is the main purpose of authentication?


b) To verify a user’s identity before granting access

[Link] of the following is NOT a common threat to data transmission?


c) Firewall protection

[Link] makes biometric authentication more secure than passwords?


b) It relies on unique physical traits (e.g., fingerprints)

[Link]-factor authentication (MFA) typically combines:


a) Two or more independent verification methods

[Link] action helps prevent replay attacks?


b) Encrypting data and using timestamps

#### *Fill in the Blanks*

1. A ____Replay ______ attack intercepts and resends data to trick systems into accepting fraudulent
requests.
2. ____Biometric ______ authentication uses traits like fingerprints or facial recognition.

3. To create a strong password, combine uppercase letters, numbers, and ____Symbols ______.

4. The ___Authentication _______ process checks user credentials against stored records to allow
access.
5. Hackers target ____ E-commerce ______ websites (e.g., banking) for man-in-the-middle attacks.

True or Flase

1. Packet sniffing can capture passwords and emails during transmission. T


2. Biometric data (e.g., fingerprints) can be easily shared between people. F
3. Multi-factor authentication (MFA) requires only a password. F
4 .Man-in-the-middle attacks aim to steal credit card details or login information. T
5. Authentication ensures only authorized users access sensitive data. T

Short Answer Questions

1. Explain one method to secure data during transmission.

Use encryption (e.g., HTTPS) to scramble data during transmission.

2. Why is biometric authentication difficult to hack?

Biometric traits (e.g., fingerprints) are unique and cannot be easily replicated.
3. What is the role of encryption in preventing replay attacks?

Encryption ensures intercepted data is unreadable, and timestamps prevent reused data.

4. Name two examples of biometric authentication technologies.

Fingerprint scanners, facial recognition.

5. How does a man-in-the-middle attack work?

A hacker secretly intercepts and alters communication between two parties to steal data

Common questions

Powered by AI

Firewalls are effective as a security measure because they act as a barrier between a trusted internal network and untrusted external networks, inspecting incoming and outgoing traffic to block malicious data packets. They are not considered a common threat to data transmission; instead, they are a protective mechanism designed to prevent unauthorized access or attacks from reaching the network. Hence, their function is fundamentally protective rather than threatening .

Packet sniffing differs from replay and man-in-the-middle attacks in that it passively captures data packets for analysis without altering them, primarily impacting confidentiality by exposing sensitive information. In contrast, replay attacks involve intercepting and resending data to trick a system, impacting data integrity by allowing unauthorized actions. Man-in-the-middle attacks actively intercept and alter communication between parties, compromising both confidentiality and integrity by potentially altering the data being exchanged .

Packet sniffing is distinguished from other types of cyber attacks by its method of capturing and analyzing data packets as they travel across a network. This passive type of attack is a significant threat to data transmission because it can discreetly capture sensitive information such as passwords and emails without altering the data flow, making it hard to detect .

Man-in-the-middle attacks compromise sensitive information by intercepting and altering communication between two parties without their knowledge. Attackers can steal data such as login credentials and credit card details by positioning themselves secretly within the communication channel, misleading both parties into believing they are directly communicating with each other . Data transmitted over less secure networks, such as those used by e-commerce and banking websites, are typically targeted .

Strong passwords contribute to authentication security by making it difficult for attackers to gain unauthorized access through guessing or brute force attacks. To increase protection, strong passwords should include a mix of uppercase and lowercase letters, numbers, and special symbols. This combination increases the complexity and unpredictability of the password, reducing the likelihood of it being compromised .

Biometric authentication is considered more secure than traditional passwords because it relies on unique physical traits such as fingerprints or facial recognition, which are difficult to replicate or share . This mitigates common security risks like password theft and unauthorized access, as biometric data cannot easily be intercepted or reused by attackers, unlike passwords that might be guessed or stolen .

Sharing biometric data is risky because it involves disclosing unchangeable physical traits that are unique to an individual. Unlike passwords, which can be easily changed if compromised, biometric traits cannot be modified. This makes recovery or countermeasures challenging if biometric data is leaked or hacked, posing a higher risk of misuse in comparison to other changeable authentication methods like passwords or security tokens .

Multi-factor authentication (MFA) enhances security by combining two or more independent verification methods, such as something you know (a password), something you have (a smartphone), or something you are (biometric data). This approach creates multiple layers of security, making it more difficult for an attacker to gain unauthorized access even if one factor (e.g., a password) is compromised .

HTTPS encryption secures data during transmission by encrypting the data exchanged between a user's browser and a website server, preventing eavesdroppers from viewing the information. This encryption is crucial for protecting sensitive user information such as login credentials and personal data from interception by malicious actors, ensuring that the communication remains confidential and intact .

Encryption plays a crucial role in preventing replay attacks by making intercepted data unreadable, ensuring that attackers cannot exploit the data even if they intercept it. Timestamps are used in conjunction with encryption to ensure that data is time-sensitive, and once a certain period has passed, the data cannot be reused. This combination of techniques prevents attackers from simply retransmitting intercepted data to perform fraudulent activities .

You might also like