Courseiva
easyMultiple Select

200-201 Practice Question: A security analyst is implementing multifactor…

A security analyst is implementing multifactor authentication. Which TWO are considered factors? (Select two.)

⚠ Common exam trap

Cisco often tests the distinction between identification (user ID) and authentication (factors that prove identity), leading candidates to mistakenly select user ID as a factor when it is only an identifier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password

A password (A) is a knowledge factor — something the user knows — and is one of the three classic authentication factor categories (knowledge, possession, inherence), so it qualifies as a factor in MFA. An RSA token (E) is a possession factor — something the user has — generating a one-time passcode (e.g., TOTP/HOTP), which is exactly the second factor MFA combines with a password. The remaining options are not authentication factors: last login time (B) is audit/log data, a user ID (C) is an identifier rather than a verifier, and security group membership (D) is an authorization attribute, not a factor used to prove identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Password

    Why this is correct

    A password is a knowledge factor: something the user knows. Multifactor authentication requires factors from different categories, so pairing it with a possession or inherence factor satisfies the two-factor requirement rather than duplicating the same category.

  • ✗

    Last login time

    Why it's wrong here

    Last login time is an audit and monitoring record, not a factor; it cannot prove identity because it is generated by the system after authentication. It tempts because it feeds anomaly detection and impossible-travel alerts, which is the correct answer when the question asks how suspicious sign-ins are detected.

  • ✗

    User ID

    Why it's wrong here

    A user ID is a claimed identifier, not a factor; it establishes who the subject says they are before any verification occurs. It tempts because it is the first field entered at sign-in, which is the correct answer when the question asks what uniquely names an account rather than what proves it.

  • ✗

    Security group membership

    Why it's wrong here

    Group membership is an authorisation attribute, not an authentication factor; it grants access after identity is proven. It tempts because groups drive role-based access control and least-privilege design, which is the right answer when the question asks how permissions are assigned rather than how identity is verified.

  • ✓

    RSA token

    Why this is correct

    An RSA token is a possession factor: something the user has. It generates time-based one-time codes, so combining it with a knowledge factor such as a password delivers genuine multifactor authentication across two distinct categories.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.