A city cloud console requires staff to approve a push notification or enter a one-time code after their password before opening the management portal. Which control is the municipality enforcing?
Select an answer to reveal the explanation.
Short Explanation
Think of the password as the front-door key and the phone approval as a deadbolt—both have to click before anyone walks into the console. That second check after the password is multifactor authentication, not a free pass for the whole help desk. Municipal cloud logins get a lot safer when something you know is paired with something you have or are.
Full Explanation
Multifactor authentication (MFA) strengthens identity proofing by requiring a second factor—such as a push approval, hardware token, or one-time code—after the password for privileged console access. Federation and SSO can streamline identity but do not by themselves add a second factor. Broad discretionary owner rights and open management-subnet SSH expand blast radius rather than enforcing MFA. Cloud+ IAM scenarios emphasize MFA for portal and privileged access.