Free Practice Quiz Question List

3 Identity and Authentication Online Quiz Questions

Use this free practice quiz with 20 questions to review 3 Identity and Authentication, test your knowledge, and prepare for your next test or exam.

20 questions
01
True or false
1 point

A person enters the correct email address for an account at sign-in. Does that alone prove that the person controls the account?

  1. A

    True

  2. B

    False

02
Written response
1 point

What is the process called that determines what an authenticated account is allowed to do?

03
Fill in the blank
1 point

A memorable can consist of several words chosen to be hard to guess.

04
Choose one
1 point

Which password strategy best follows the guidance for protecting an important account?

  1. A

    Use a short password with a predictable symbol substitution.

  2. B

    Use a long, unique password for the account.

  3. C

    Change the password on a fixed schedule, even when it has not been exposed.

  4. D

    Reuse a familiar password so it is easier to remember.

05
True or false
1 point

Using two different passwords for one sign-in provides two distinct authentication factors.

  1. A

    True

  2. B

    False

06
Written response
1 point

A phone used as an authenticator belongs to which authentication factor category?

07
Fill in the blank
1 point

Store recovery codes somewhere secure and from the account they unlock.

08
Choose one
1 point

You need to sign in to a service, but an unexpected message offers a sign-in link. What is the safest approach?

  1. A

    Open the sign-in link in an unexpected message.

  2. B

    Use the service’s trusted app or enter an address you already know.

  3. C

    Reply to the message to confirm that its link is genuine.

  4. D

    Use the link if the message includes the account’s email address.

09
Choose all
1 point

Select all sign-in combinations that use two distinct authentication factor types.

  1. A

    A password and a code from an authenticator app.

  2. B

    A password and a second password.

  3. C

    A password and a security key.

  4. D

    A PIN and a password.

10
Choose one
1 point

A user relies on a phone to receive authentication prompts. Which action best protects that part of the sign-in process?

  1. A

    Leave the device used for sign-in prompts unlocked and unattended.

  2. B

    Disable account protections on the device that receives prompts.

  3. C

    Secure the device or account used to receive authentication prompts.

  4. D

    Share the device’s sign-in credentials with other people.

11
Choose all
1 point

You suspect that an account has been compromised. Select all recommended steps to take.

  1. A

    Change the password from a trusted device.

  2. B

    Revoke unfamiliar active sessions.

  3. C

    Keep all existing sessions active without checking them.

  4. D

    Review the account’s recovery details and MFA methods.

12
Choose one
1 point

When a service offers multiple sign-in methods, which option is designed to resist many phishing attacks by binding sign-in to the legitimate service?

  1. A

    A password followed by another password.

  2. B

    A passkey or security key.

  3. C

    A code sent by text message.

  4. D

    A one-time code that the user can read aloud to someone requesting it.

13
Open ended
1 point

Explain why using a unique password for each account reduces the risk that a breach at one service will affect accounts elsewhere.

14
Choose one
1 point

Which routine practice is most useful for noticing unfamiliar activity on an account?

  1. A

    Review sign-in alerts, devices, and active sessions

  2. B

    Change the password on a fixed schedule, regardless of account activity

  3. C

    Keep recovery details unchanged

  4. D

    Approve every sign-in request

15
Choose one
1 point

You still have access to an account, but its recovery email address is no longer accessible. What is the best step to take?

  1. A

    Wait until the old address or number is needed to recover the account

  2. B

    Remove every recovery option, even if doing so leaves no way to regain access

  3. C

    Update the account's recovery details while you can still access it

  4. D

    Use the old contact details for another account instead

16
Choose one
1 point

A sign-in approval request appears on your device, but you did not try to sign in. What should you do?

  1. A

    Approve it because the service sent the prompt

  2. B

    Approve it, then check the account later

  3. C

    Ask someone else to approve it for you

  4. D

    Do not approve it

17
Choose one
1 point

A deceptive message tricks a person into revealing their password. What kind of attack does this describe?

  1. A

    Phishing

  2. B

    Authorization

  3. C

    Account recovery

  4. D

    Biometric authentication

18
True or false
1 point

According to the material, it is good practice to change a password at fixed intervals even when there is no indication that it has been exposed.

  1. A

    True

  2. B

    False

19
Written response
1 point

What is the name of an attack in which someone tricks a person into revealing a password?

20
Written response
1 point

What type of password changes does NIST advise against?