mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: A network administrator is implementing a new…
A network administrator is implementing a new security policy that requires all employees to use multi-factor authentication (MFA) when accessing email from external networks. However, several employees report that they cannot receive SMS codes while traveling internationally. Which design change best balances security and usability?
⚠ Common exam trap
Cisco often tests the distinction between 'something you have' (phone/authenticator app) and 'something you receive' (SMS), where candidates mistakenly think SMS is the only 'something you have' factor, missing that TOTP apps provide the same factor without network dependency.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow the use of authenticator apps that generate time-based one-time passwords (TOTP).
TOTP authenticator apps (e.g., Google Authenticator, Microsoft Authenticator) generate one-time passwords locally on the user's device without requiring cellular network connectivity. This solves the international SMS delivery problem while maintaining strong MFA security, as the TOTP algorithm (RFC 6238) uses a shared secret and the current time to produce codes that are valid for a short window (typically 30 seconds).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allow the use of authenticator apps that generate time-based one-time passwords (TOTP).
Why this is correct
TOTP apps work offline and are a common alternative to SMS.
- ✗
Allow email access without MFA from trusted countries.
Why it's wrong here
Trusting countries does not address the security requirement.
- ✗
Provide hardware tokens to all traveling employees.
Why it's wrong here
Hardware tokens are expensive and may not be available immediately.
- ✗
Disable MFA for users who travel frequently.
Why it's wrong here
Disabling MFA removes the security requirement, violating policy.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.