A person enters the correct email address for an account at sign-in. Does that alone prove that the person controls the account?
3 Identity and Authentication Online Quiz Questions
Use this free practice quiz with 20 questions to review 3 Identity and Authentication, test your knowledge, and prepare for your next test or exam.
What is the process called that determines what an authenticated account is allowed to do?
A memorable can consist of several words chosen to be hard to guess.
Which password strategy best follows the guidance for protecting an important account?
- A
Use a short password with a predictable symbol substitution.
- B
Use a long, unique password for the account.
- C
Change the password on a fixed schedule, even when it has not been exposed.
- D
Reuse a familiar password so it is easier to remember.
Using two different passwords for one sign-in provides two distinct authentication factors.
- A
True
- B
False
A phone used as an authenticator belongs to which authentication factor category?
Store recovery codes somewhere secure and from the account they unlock.
You need to sign in to a service, but an unexpected message offers a sign-in link. What is the safest approach?
- A
Open the sign-in link in an unexpected message.
- B
Use the service’s trusted app or enter an address you already know.
- C
Reply to the message to confirm that its link is genuine.
- D
Use the link if the message includes the account’s email address.
Select all sign-in combinations that use two distinct authentication factor types.
- A
A password and a code from an authenticator app.
- B
A password and a second password.
- C
A password and a security key.
- D
A PIN and a password.
A user relies on a phone to receive authentication prompts. Which action best protects that part of the sign-in process?
- A
Leave the device used for sign-in prompts unlocked and unattended.
- B
Disable account protections on the device that receives prompts.
- C
Secure the device or account used to receive authentication prompts.
- D
Share the device’s sign-in credentials with other people.
You suspect that an account has been compromised. Select all recommended steps to take.
- A
Change the password from a trusted device.
- B
Revoke unfamiliar active sessions.
- C
Keep all existing sessions active without checking them.
- D
Review the account’s recovery details and MFA methods.
When a service offers multiple sign-in methods, which option is designed to resist many phishing attacks by binding sign-in to the legitimate service?
- A
A password followed by another password.
- B
A passkey or security key.
- C
A code sent by text message.
- D
A one-time code that the user can read aloud to someone requesting it.
Explain why using a unique password for each account reduces the risk that a breach at one service will affect accounts elsewhere.
Which routine practice is most useful for noticing unfamiliar activity on an account?
- A
Review sign-in alerts, devices, and active sessions
- B
Change the password on a fixed schedule, regardless of account activity
- C
Keep recovery details unchanged
- D
Approve every sign-in request
You still have access to an account, but its recovery email address is no longer accessible. What is the best step to take?
- A
Wait until the old address or number is needed to recover the account
- B
Remove every recovery option, even if doing so leaves no way to regain access
- C
Update the account's recovery details while you can still access it
- D
Use the old contact details for another account instead
A sign-in approval request appears on your device, but you did not try to sign in. What should you do?
- A
Approve it because the service sent the prompt
- B
Approve it, then check the account later
- C
Ask someone else to approve it for you
- D
Do not approve it
A deceptive message tricks a person into revealing their password. What kind of attack does this describe?
- A
Phishing
- B
Authorization
- C
Account recovery
- D
Biometric authentication
According to the material, it is good practice to change a password at fixed intervals even when there is no indication that it has been exposed.
- A
True
- B
False
What is the name of an attack in which someone tricks a person into revealing a password?
What type of password changes does NIST advise against?