Question 1 of 3
A financial institution is implementing Multi-Factor Authentication (MFA) to enhance the security of its online banking platform. The institution decides to use a combination of something the user knows (a password), something the user has (a mobile device for receiving a one-time code), and something the user is (biometric verification). During a security audit, it is discovered that the password is stored in a hashed format, but the hashing algorithm used is outdated and vulnerable to attacks. Additionally, the one-time codes are sent via SMS, which is susceptible to interception. Given these vulnerabilities, which approach should the institution prioritize to strengthen its MFA implementation while ensuring compliance with industry standards?
Upgrade the hashing algorithm for passwords and switch to an authenticator app for generating one-time codes.
Continue using the current hashing algorithm and enhance SMS security measures.
Rely solely on biometric verification as the primary authentication method.
Implement a security awareness program for users to educate them about password strength.

Preparing for Microsoft AZ-500 Microsoft Azure Security Technologies? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free