Free Online Flashcard Deck

3 Identity and Authentication Free Online FlashCards

Study 3 Identity and Authentication with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.

12 cards
01
Front

What is a digital identity?

Back

A digital identity is the information a service associates with an account.

02
Front

Does a username prove account ownership?

Back

An identifier names an account, but does not prove that the person presenting it controls that account.

03
Front

How do authentication and authorization differ?

Back

Authentication checks control of an account’s authenticators; authorization determines what the authenticated account may do.

04
Front

What are the three common authentication-factor categories?

Back

Something you know, such as a password; something you have, such as a security key; or something you are, such as a fingerprint.

05
Front

Do two passwords count as multifactor authentication?

Back

No. Both passwords are something you know, so they are the same factor category rather than two distinct factors.

06
Front

Why should every account have a unique password?

Back

Use a long, unique password for each account. Uniqueness prevents a password exposed at one service from being reused to attack another account.

07
Front

How can a password manager improve account security?

Back

It can create and store strong, distinct passwords, so you do not need to memorize each one.

08
Front

What is a passphrase?

Back

A memorable phrase made from several words chosen to be hard to guess; it can be an effective password.

09
Front

Why are predictable password substitutions weak?

Back

Predictable substitutions add little protection; length and uniqueness matter more than changes such as turning `password` into `Password1!`.

10
Front

When should a password be changed?

Back

NIST advises against arbitrary periodic changes. Change a password if it may have been exposed or compromised.

11
Front

What does MFA add to account protection?

Back

MFA requires more than one distinct factor. It makes account takeover harder if one factor is stolen, but does not eliminate every risk.

12
Front

Which sign-in methods resist many phishing attacks?

Back

Passkeys and security keys use cryptographic authentication bound to the legitimate service, making them resistant to many phishing attacks.