What is multi-factor authentication (MFA)?
- A.Authentication requiring two or more independent factors from different categories: something you know, something you have, or something you are
- B.Using the same password for two different systems, paired under Requirement 8.3.9 with a change at least every ninety days wherever a password is the only authentication factor in use
- C.Using a very long password, given that the standard treats two instances of the same authentication factor as multi-factor for Level 1 merchants
- D.Logging in from two different devices, given that multi-factor authentication is required only for remote access originating outside the country
Why A is correct
MFA requires two or more independent authentication factors from different categories (knowledge, possession, inherence), making it significantly harder for unauthorized users to gain access even if one factor is compromised.
Know someone studying for PCI DSS? Send them this one.