Authenticating a user includes providing a plurality of questions based on
user related information stored in at least one data source, wherein none
of the plurality of questions is password related. At least one of the
plurality of questions is presented to the user in response to receiving
a request from the user to access one or more protected resources. Access
is granted to the authorized set of protected resources if the user
correctly answers each of the at least one questions presented. According
to the present invention, the user's identity is authenticated without
requiring the user to provide a password or biometric data, and without
requiring the user to enroll prior to access.