200-301 exam dumps

200-301 practice question 429 of 506

Cisco Certified Network Associate. Free level, Cisco. Free question with the correct answer and a full explanation.

200-301 Question 429

Select 3

A network administrator is tasked with enhancing access security for a corporate VPN. The company requires a solution that offers stronger authentication than just passwords. Which of the following methods should the administrator implement to meet this requirement?

  1. A

    Enable multifactor authentication using a mobile authenticator app

  2. B

    Require users to change their passwords every 30 days

  3. C

    Implement biometric authentication, such as fingerprint or facial recognition

  4. D

    Deploy digital certificates for user authentication

  5. E

    Use a shared password for all users to simplify access

Show answer and explanation

Correct answers: A, C, D

Explanation

To enhance access security, the administrator should implement password alternatives such as multifactor authentication, biometrics, or digital certificates. These methods provide stronger authentication mechanisms and reduce reliance on passwords alone, which are more vulnerable to breaches or attacks. Regular password changes or shared passwords do not address the limitations of passwords and are not considered valid alternatives.

  • A. Correct.

    Multifactor authentication (MFA) enhances security by requiring two or more authentication factors, such as something the user knows (password), something the user has (mobile app), or something the user is (biometrics). This is a strong alternative to passwords alone.

  • B. Incorrect.

    Requiring regular password changes does not address the limitations of password-based authentication itself, and it is not considered an alternative to passwords.

  • C. Correct.

    Biometric authentication is a secure and user-friendly alternative that uses unique physical traits, making it difficult for attackers to replicate or breach.

  • D. Correct.

    Digital certificates provide a secure way to authenticate users without relying solely on passwords. They use public key infrastructure (PKI) to verify identity.

  • E. Incorrect.

    Using a shared password for all users significantly increases security risks and does not meet the requirement for stronger authentication.

Timed practice exam

Take a 200-301 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam