Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: A network administrator is implementing a new…

A network administrator is implementing a new security policy that requires all employees to use multi-factor authentication (MFA) when accessing email from external networks. However, several employees report that they cannot receive SMS codes while traveling internationally. Which design change best balances security and usability?

⚠ Common exam trap

Cisco often tests the distinction between 'something you have' (phone/authenticator app) and 'something you receive' (SMS), where candidates mistakenly think SMS is the only 'something you have' factor, missing that TOTP apps provide the same factor without network dependency.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Allow the use of authenticator apps that generate time-based one-time passwords (TOTP).

TOTP authenticator apps (e.g., Google Authenticator, Microsoft Authenticator) generate one-time passwords locally on the user's device without requiring cellular network connectivity. This solves the international SMS delivery problem while maintaining strong MFA security, as the TOTP algorithm (RFC 6238) uses a shared secret and the current time to produce codes that are valid for a short window (typically 30 seconds).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Allow the use of authenticator apps that generate time-based one-time passwords (TOTP).

    Why this is correct

    TOTP apps work offline and are a common alternative to SMS.

  • Allow email access without MFA from trusted countries.

    Why it's wrong here

    Trusting countries does not address the security requirement.

  • Provide hardware tokens to all traveling employees.

    Why it's wrong here

    Hardware tokens are expensive and may not be available immediately.

  • Disable MFA for users who travel frequently.

    Why it's wrong here

    Disabling MFA removes the security requirement, violating policy.

About these practice questions

This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.