Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 80

What is the MOST effective way to reduce security risks associated with SSO (Single Sign-On)?
  • A Implementing multi-factor authentication
  • B Implementing biometric authentication
  • C Implementing strong password policies
  • D Implementing single-factor authentication
Reveal correct answer

Correct answer: A

Explanation

The correct answer: Implementing multi-factor authentication: Multi-factor authentication (MFA) is currently recognized as the most effective way to reduce security risks associated with single sign-on (SSO). SSO simplifies the authentication process by enabling users to log in to multiple applications and systems with a single set of credentials, but this also makes it a valuable target for cybercriminals. If a hacker obtains the SSO credentials, they can gain access to all systems the user is authenticated for. Multi-factor authentication adds extra layers of security by requiring the user to provide two or more separate forms of identification before access is granted. These factors can be something they know (like a password), something they have (like a hardware token or a code sent to their phone), or something they are (biometric information). This means that even if an attacker gains access to one factor (such as the password), they still won't be able to authenticate without the other factor(s), which are much harder to obtain. Therefore, MFA effectively minimizes the risk associated with SSO. The incorrect answers: Implementing strong password policies: While strong password policies are an essential part of any security strategy, they are not the most effective way to reduce risks associated with SSO. Even the strongest password can be compromised, for example, through phishing, keylogging, or brute force attacks. And once the SSO password is compromised, the attacker has access to all systems authenticated by the SSO. While strong password policies can make it more difficult for attackers, they don't offer the same level of security as multi-factor authentication. Implementing biometric authentication: Biometric authentication, such as fingerprint or facial recognition, can provide a strong form of security. When used as a single factor in an SSO system, it can still be vulnerable. If the biometric data is somehow compromised, all applications connected through SSO would be accessible to an attacker. Unlike passwords, biometric data can't be changed if it's compromised, which makes recovery from a security breach more challenging. Biometric authentication can be a part of a multi-factor authentication system, but on its own, it's not as effective as MFA. Implementing single-factor authentication: Single-factor authentication, such as using only a password, is the least secure option among these. It's even more vulnerable in an SSO context because if the single factor (the password) is compromised, the attacker can access multiple systems or applications. Compared to multi-factor authentication, which adds extra layers of security, single-factor authentication is easier to breach and does not significantly reduce the security risks associated with SSO.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need