What is knowledge-based authentication? | Definition from TechTarget (2024)

Knowledge-based authentication (KBA) is an authentication method in which users are asked to answer at least one secret question. KBA is often used as a component in multifactor authentication (MFA) and for self-service password retrieval.

A strong KBA question should meet the following four criteria:

  1. The question should be appropriate for a large segment of the population.
  2. The answer should be something easily remembered.
  3. The question should only have one correct answer.
  4. The answer should not be easy to guess or discover through research.

KBA questions can be static or dynamic. Both methods rely on the assumption that if someone knows the correct answers to the secret questions, their identity has been confirmed.

In a static scheme, the end user preselects the questions to be asked and provides the correct answers. The host stores the question-and-answer pairs and uses them later to verify the person's identity. KBA questions can be factual, such as: "Where did you spend your honeymoon?" or "How many pets do you have?" Or they can be about preferences, such as: "What is your favorite food?" or "Who was your favorite teacher?" The problem with static KBA questions is that if someone has shared that information on social media, for example, the answer can be easily guessed.

In a dynamic scheme, the end user has no idea what question will be asked. Instead, the question-and-answer pairs are selected from harvested data, such as public records. Examples of dynamic KBA questions include: "What street address did you live on when you were 10 years old?" or "What color Ford Mustang was registered to you in New York state in 2002?" Although the answers to dynamic questions could be researched, it would take time. If the respondent does not answer a dynamic question within a certain time period, the question is discarded and treated as a wrong answer.

Experts don't consider knowledge-based authentication to be secure enough on its own, particularly in the age of social media where people tend to share a lot of information about themselves. Using KBA as part of MFA is preferred, which would strengthen the authentication method for accounts. MFA is recommended over KBA, especially with the rise of remote and hybrid work.

This article was written in 2015. TechTarget editors revised it in 2023 to improve the reader experience.

This was last updated in July 2023

Continue Reading About knowledge-based authentication

Related Terms

What is identity threat detection and response (ITDR)?
Identity threat detection and response (ITDR) is a collection of tools and best practices aimed at defending against cyberattacks...Seecompletedefinition
What is LDAP (Lightweight Directory Access Protocol)?
LDAP (Lightweight Directory Access Protocol) is a software protocol used for locating data about organizations, individuals and ...Seecompletedefinition
What is passive keyless entry (PKE)?
Passive keyless entry (PKE) is an automotive security system that operates automatically when the user is in proximity to the ...Seecompletedefinition

Dig Deeper on Identity and access management

What is knowledge-based authentication? | Definition from TechTarget (2024)
Top Articles
Bitstamp Review: A Deep Dive into the Veteran Crypto Exchange
Do Solar Panels Increase Home Value? (2024 Guide)
Use Copilot in Microsoft Teams meetings
Christian McCaffrey loses fumble to open Super Bowl LVIII
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Paris 2024: Kellie Harrington has 'no more mountains' as double Olympic champion retires
Health Benefits of Guava
Trade Chart Dave Richard
How to Type German letters ä, ö, ü and the ß on your Keyboard
Umn Biology
Pollen Count Central Islip
Housing Intranet Unt
[2024] How to watch Sound of Freedom on Hulu
OpenXR support for IL-2 and DCS for Windows Mixed Reality VR headsets
The Shoppes At Zion Directory
Meritas Health Patient Portal
Moonshiner Tyler Wood Net Worth
Truck Trader Pennsylvania
Are They Not Beautiful Wowhead
Is Grande Internet Down In My Area
Missouri Highway Patrol Crash
Ubg98.Github.io Unblocked
Where Is George The Pet Collector
Munis Self Service Brockton
How To Find Free Stuff On Craigslist San Diego | Tips, Popular Items, Safety Precautions | RoamBliss
Dtm Urban Dictionary
Danielle Moodie-Mills Net Worth
Pioneer Library Overdrive
Southtown 101 Menu
Bfri Forum
Have you seen this child? Caroline Victoria Teague
Lucky Larry's Latina's
Gwu Apps
Acadis Portal Missouri
Manatee County Recorder Of Deeds
Craigslist Pets Huntsville Alabama
20 Best Things to Do in Thousand Oaks, CA - Travel Lens
Flags Half Staff Today Wisconsin
Discover Things To Do In Lubbock
The Wait Odotus 2021 Watch Online Free
LumiSpa iO Activating Cleanser kaufen | 19% Rabatt | NuSkin
Mychart Mercy Health Paducah
Content Page
Autozone Battery Hold Down
Page 5747 – Christianity Today
Kushfly Promo Code
Evil Dead Rise - Everything You Need To Know
Tyrone Unblocked Games Bitlife
Twizzlers Strawberry - 6 x 70 gram | bol
Zom 100 Mbti
Factorio Green Circuit Setup
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 5417

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.