Information & AI guides →

Information & AI · Security

Security basics: verify identity and limit permission

Being able to sign in is different from being allowed to read every file. Replace the single label secure with more specific questions: whose identity is verified, which actions are permitted, and how far a failure could spread. Each question requires different evidence.

This guide starts with credentials and access permissions. One defense does not prevent every possible attack. Understand the available mechanisms, the scope required for your work and the paths used to recover access.

Try this topic in a quiz

This opens the setup screen with this subject and topic selected. Check the mode and question count before you start.

Authorization still matters after authentication

Authentication verifies identity; authorization decides what that identity may do. A signed-in member of a shared workspace does not necessarily have permission to change administrative settings or read another person's records. Explain who the user is separately from which actions are allowed.

Consider whether a read-only task also needs permission to edit or delete. Least privilege limits access to what the task requires. Hiding a button is not a complete access-control decision: the system that actually handles a request must enforce the applicable permission.

Identify how one breach can spread

Credential stuffing tests username/password pairs stolen from one service against another. Reusing the same credentials creates an opportunity for a breach in one place to affect other accounts. Separate companies can still be attacked with the same pair if that pair remains valid.

A password manager can help generate and store different long passwords for different services. Its own protection and recovery arrangements also matter. Compare the convenience of reusing one memorable credential with the wider exposure that reuse creates after a breach.

Combine different factors rather than repeated questions

Multifactor authentication combines distinct categories such as knowledge, possession and an inherent personal characteristic. A password and a possessed authenticator use different categories; a password and a PIN are both knowledge. Two screens or two questions do not automatically constitute two different factors.

Additional factors also need recovery paths when unavailable. Recovery codes and factor changes should not be treated as unrelated to account protection. Rather than using MFA as a universal seal of safety, identify the factors checked and the ways they can be reset.

TRY & READ

Check your understanding with examples

Compare the choices before opening the answer and explanation. Reading an example does not save a test answer or score.

Example 1 · Security

After establishing a user's identity, what decides whether that user may read a file?

  1. Authorization
  2. Compression
  3. Character-encoding conversion
  4. Display zoom
Read the answer and explanation

Answer: Authorization

Authentication establishes identity; authorization determines allowed actions. Logging in does not imply access to every file.

Sources for this example

  • Authorization - OWASP Cheat Sheet Series

    Attribute and relationship based authorization; IDOR; Deny by default; Introduction authentication vs authorization; Least privilege; Validate permissions on every request

    Source checked: 2026-10-05

Example 2 · Security

Which habit increases risk when credentials stolen from one service are tried on another?

  1. Reusing a password across services
  2. Using different strong passwords per service
  3. Removing unnecessary accounts
  4. Adding two-factor authentication
Read the answer and explanation

Answer: Reusing a password across services

Reused credentials spread the impact of a breach to other services; this attack is called credential stuffing.

Sources for this example

Example 3 · Security

What is the main purpose of combining a password with verification using an authenticator the user possesses?

  1. Strengthen authentication with different factors
  2. Publish the password
  3. Eliminate authorization checks
  4. Remove backups
Read the answer and explanation

Answer: Strengthen authentication with different factors

Combine different factors such as knowledge and possession; asking for the same password twice does not add a factor.

Sources for this example

Sources for this guide

Continue with a quiz

Topics: Security. Range: Everyday knowledge, Broader knowledge, General knowledge. Difficulty: Basic, Standard. These are selected initially. You can change these on the setup screen.

Try this topic in a quiz

A test shows explanations after submission. Continuous challenge explains each answer. Review uses unresolved mistakes recorded on this device. Casual mode does not update learning records.

Enjoyed it? Share the link

Only the page address is shared. Your saves and results are not included.

Link to this page