What is knowledge-based authentication? | Definition from TechTarget (2024)

Knowledge-based authentication (KBA) is an authentication method in which users are asked to answer at least one secret question. KBA is often used as a component in multifactor authentication (MFA) and for self-service password retrieval.

A strong KBA question should meet the following four criteria:

  1. The question should be appropriate for a large segment of the population.
  2. The answer should be something easily remembered.
  3. The question should only have one correct answer.
  4. The answer should not be easy to guess or discover through research.

KBA questions can be static or dynamic. Both methods rely on the assumption that if someone knows the correct answers to the secret questions, their identity has been confirmed.

In a static scheme, the end user preselects the questions to be asked and provides the correct answers. The host stores the question-and-answer pairs and uses them later to verify the person's identity. KBA questions can be factual, such as: "Where did you spend your honeymoon?" or "How many pets do you have?" Or they can be about preferences, such as: "What is your favorite food?" or "Who was your favorite teacher?" The problem with static KBA questions is that if someone has shared that information on social media, for example, the answer can be easily guessed.

In a dynamic scheme, the end user has no idea what question will be asked. Instead, the question-and-answer pairs are selected from harvested data, such as public records. Examples of dynamic KBA questions include: "What street address did you live on when you were 10 years old?" or "What color Ford Mustang was registered to you in New York state in 2002?" Although the answers to dynamic questions could be researched, it would take time. If the respondent does not answer a dynamic question within a certain time period, the question is discarded and treated as a wrong answer.

Experts don't consider knowledge-based authentication to be secure enough on its own, particularly in the age of social media where people tend to share a lot of information about themselves. Using KBA as part of MFA is preferred, which would strengthen the authentication method for accounts. MFA is recommended over KBA, especially with the rise of remote and hybrid work.

This article was written in 2015. TechTarget editors revised it in 2023 to improve the reader experience.

This was last updated in July 2023

Continue Reading About knowledge-based authentication

Related Terms

What is identity threat detection and response (ITDR)?
Identity threat detection and response (ITDR) is a collection of tools and best practices aimed at defending against cyberattacks...Seecompletedefinition
What is LDAP (Lightweight Directory Access Protocol)?
LDAP (Lightweight Directory Access Protocol) is a software protocol used for locating data about organizations, individuals and ...Seecompletedefinition
What is passive keyless entry (PKE)?
Passive keyless entry (PKE) is an automotive security system that operates automatically when the user is in proximity to the ...Seecompletedefinition

Dig Deeper on Identity and access management

What is knowledge-based authentication? | Definition from TechTarget (2024)
Top Articles
Benefits of forming a Limited Liability Company (LLC)
Etiqueta de envío: qué es y cómo se crea
Ceton Village Diggy
Fen No Results
El Puerto Harrisonville Mo Menu
57 Freeway Accident Today 2023
Binghamton Legacy Obits
415-261-2242
Walmart Careers Stocker
Goddess Spa Staten Island
The Financial Benefits of Earning a College Degree
Seat Number Usana Seating Chart With Rows
pittsburgh gigs - craigslist
Craigslist Westchester Free Stuff
Richard Sambade Obituary
Optum Primary Care - Winter Park Aloma
Charm City Kings 123Movies
Lorain County Busted Mugshots
Bfs Lunch Menu
Peach Sorbet Read Online
Paddie’s Polygel Nail Expert Kit
Braulio Babo Castellanos
Denver Post Replica Login
George Hamilton Deck Commercial
Busted Newspaper Mclennan County
Craigslist Sfbay
New England Revolution vs CF Montréal - En vivo MLS de Estados Unidos - 2024 - Fase Regular
Yalelightingconcepts
Cellabsorbv
Chico Ca Craigslist
Doylestown (Pennsylvania) – Travel guide at Wikivoyage
Qmf Bcbs Prefix
CDT to CST Converter - Savvy Time
Katopunk Pegging
Manage limits.conf configurations in Splunk Cloud Platform
Gasbuddy Bakersfield Costco
Marie Temara Feet Pics
Dollar General Warehouse Pay Rate
Happy Garden Fairmont Menu
Bee & Willow™ 31-Piece LED Tea … curated on LTK
Makedonska Kursna Lista
Enduring Word John 15
Wfin Local News
Iowa State Map Campus
1-866-464-7761
Infinite Campus Farmingdale
Topeka Pets Craigslist
Missing 2023 Showtimes Near Cinemark Beaumont 15 And Xd
Obituaries In Asheville Citizen-Times
Syracuse Pets Craigslist
Brake Masters 228
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 5417

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.