Question 1 Report
A business uses different methods to verify the identity of customers accessing its online services.
| Verification method | How it works | One limitation |
|---|---|---|
| Knowledge-based questions | ||
| Email verification link | ||
| SMS one-time passcode |
(a) Complete the table by describing how each method works and giving one limitation. [6]
(b) Explain why using a combination of these methods is more secure than using any single method. [2]
(a) How each verification method works and one limitation [6]
| Method | How It Works | One Limitation |
|---|---|---|
| Knowledge-based questions | The user is asked questions about personal information that they should know the answers to, such as their mother's maiden name, their first school, or their childhood pet. [1] | The answers can sometimes be found on social media profiles or public records, or guessed by someone who knows the user personally, making this method vulnerable to social engineering. [1] |
| Email verification link | A unique, time-limited link is sent to the user's registered email address. The user must click the link to confirm their identity and prove they have access to that email account. [1] | If the user's email account has been compromised (e.g. through a phishing attack or password reuse), an attacker could click the verification link and impersonate the user. [1] |
| SMS one-time passcode | A temporary numeric code is sent via SMS to the user's registered mobile phone number. The code must be entered into the website within a short time limit (typically 2-5 minutes) to confirm identity. [1] | The code could be intercepted through SIM swapping (where an attacker convinces the phone provider to transfer the number to a new SIM) or if the phone is stolen. [1] |
(b) Why combining methods is more secure [2]
Using a combination ensures that even if one method is compromised (e.g. a hacker knows the answer to a security question), they still need to bypass additional methods to gain access. [1]
Different methods verify identity using different channels (knowledge, email, phone), reducing the chance that a single attack vector (e.g. phishing) can defeat all of them simultaneously. [1]
Everything you need to excel in your exams