Finance staff reach the treasury network over VPN using passwords alone. Which authentication strategy change is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Password-only VPN into treasury is a single lock on a vault door. Add MFA—or move toward phishing-resistant passwordless—so stolen passwords alone do not open the books. Faster logins, quieter logs, and shared chat passwords push risk the wrong way.
Full Explanation
Authentication, authorization, and accounting for sensitive remote access should not rely on a single memorized secret. MFA or passwordless authenticators raise assurance for finance and other high-risk populations connecting over VPN. Shared passwords and the absence of session accounting weaken both authentication and accountability. CISSP-level AAA design pairs stronger authenticators with logged, authorized sessions rather than convenience-driven single-factor remote access.