MFA: Password Policy Flashcards

1
Q

Password policy

A

Set a minimum password length

Require specific character types:
- Including uppercase letters
- lowercase letters
- numbers
- non-alphanumeric characters

Allow all IAM users to change their own passwords

Require users to change their password after some time (password expiration).

Prevent password re-use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Multi Factor Authentication - MFA

A

Password you know + security device you own (Microsoft Authenticator)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

MFA devices options

A

Virtual MFA device - multiple tokens on a single device:
- Google Authenticator (phone only)
- Authy (phone only)

Universal 2nd Factor (U2F) Security Key - multiple root and IAM users:
- YubiKey by Yubico (3rd party)

Hardware Key Fob MFA device:
- Provided by Gemalto (3rd party)

Hardware Key Fob MFA device for AWS GovCloud (US):
- Provided by SurePassID (3rd party)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly