What is multi-factor authentication (MFA) and why does the Protect function emphasize it?
- A.Using multiple passwords for the same account, assuming that encryption satisfies every Protect subcategory on its own and that Protect is satisfied by perimeter firewalls
- B.Authenticating with multiple biometric scans of the same type, as a Community Profile automatically overrides an organization's own Target Profile wherever the two conflict
- C.Having multiple users authenticate the same request, which rests on the claim that Protect forbids compensating controls and that Protect requires a single security vendor
- D.Authentication requiring two or more factors (something you know, have, or are), significantly reducing the risk of unauthorized access even when one factor is compromised
Why D is correct
MFA combines different authentication factors (password + token, biometric + smart card), making it much harder for attackers to gain access even with stolen credentials.
Know someone studying for NIST CSF? Send them this one.