Security basics: verify identity and limit permission
Being able to sign in is different from being allowed to read every file. Replace the single label secure with more specific questions: whose identity is verified, which actions are permitted, and how far a failure could spread. Each question requires different evidence.
This guide starts with credentials and access permissions. One defense does not prevent every possible attack. Understand the available mechanisms, the scope required for your work and the paths used to recover access.
This opens the setup screen with this subject and topic selected. Check the mode and question count before you start.
Authorization still matters after authentication
Authentication verifies identity; authorization decides what that identity may do. A signed-in member of a shared workspace does not necessarily have permission to change administrative settings or read another person's records. Explain who the user is separately from which actions are allowed.
Consider whether a read-only task also needs permission to edit or delete. Least privilege limits access to what the task requires. Hiding a button is not a complete access-control decision: the system that actually handles a request must enforce the applicable permission.
Identify how one breach can spread
Credential stuffing tests username/password pairs stolen from one service against another. Reusing the same credentials creates an opportunity for a breach in one place to affect other accounts. Separate companies can still be attacked with the same pair if that pair remains valid.
A password manager can help generate and store different long passwords for different services. Its own protection and recovery arrangements also matter. Compare the convenience of reusing one memorable credential with the wider exposure that reuse creates after a breach.
Combine different factors rather than repeated questions
Multifactor authentication combines distinct categories such as knowledge, possession and an inherent personal characteristic. A password and a possessed authenticator use different categories; a password and a PIN are both knowledge. Two screens or two questions do not automatically constitute two different factors.
Additional factors also need recovery paths when unavailable. Recovery codes and factor changes should not be treated as unrelated to account protection. Rather than using MFA as a universal seal of safety, identify the factors checked and the ways they can be reset.
TRY & READ
Check your understanding with examples
Compare the choices before opening the answer and explanation. Reading an example does not save a test answer or score.
Example 1 · Security
After establishing a user's identity, what decides whether that user may read a file?
Authorization
Compression
Character-encoding conversion
Display zoom
Read the answer and explanation
Answer: Authorization
Authentication establishes identity; authorization determines allowed actions. Logging in does not imply access to every file.
Attribute and relationship based authorization; IDOR; Deny by default; Introduction authentication vs authorization; Least privilege; Validate permissions on every request
Source checked: 2026-10-05
Example 2 · Security
Which habit increases risk when credentials stolen from one service are tried on another?
Reusing a password across services
Using different strong passwords per service
Removing unnecessary accounts
Adding two-factor authentication
Read the answer and explanation
Answer: Reusing a password across services
Reused credentials spread the impact of a breach to other services; this attack is called credential stuffing.
Topics: Security. Range: Everyday knowledge, Broader knowledge, General knowledge. Difficulty: Basic, Standard. These are selected initially. You can change these on the setup screen.
A test shows explanations after submission. Continuous challenge explains each answer. Review uses unresolved mistakes recorded on this device. Casual mode does not update learning records.