Authentication
Proving a claimed identity by showing possession and control of one or more authenticators bound to that account; it follows identification and comes before authorisation.
Authentication is the step that tests a claim of identity. NIST SP 800-63B-4 defines it as the process by which a claimant proves possession and control of one or more authenticators bound to a subscriber account, to show that they are the subscriber associated with it. A username is only identification, a claim that establishes nothing on its own; authentication supplies the proof, using one or more authentication factors.
It sits between identification and authorisation. A system can authenticate a user perfectly and still grant the wrong access, because deciding what an identity may do is a separate function. Authentication also has limits in the other direction: it proves control of an authenticator that was bound at enrolment, so what it says about the real person depends on the identity proofing done before that binding. Strength is graded separately from proofing, as an authentication assurance level. Multi-factor authentication raises it, and mutual authentication extends it so that the server proves itself to the client as well.
Exam relevance: questions in this area tend to test the order and boundaries of identification, authentication, authorisation and accounting. Candidates are expected to keep “proving who you are” apart from “deciding what you may do”, and to avoid assuming that strong authentication proves more about a person than the enrolment behind it.