hardMultiple ChoiceObjective-mapped
MFA Policy for Legacy Applications
A company is implementing a security policy that requires all employees to use multi-factor authentication (MFA) when accessing corporate resources remotely. However, during a recent security audit, it was found that several employees have been using app passwords for legacy applications that do not support MFA. What is the best practice under this policy?
Quick Answer
The correct answer is to create a separate policy for legacy applications with compensating controls. This is because app passwords, while allowing legacy apps to bypass MFA, are essentially static credentials that do not satisfy true multi-factor authentication and can be exploited if stolen. A separate policy for legacy applications should enforce compensating controls such as network segmentation, strict monitoring, and conditional access to mitigate the risk without forcing the immediate retirement of critical but outdated systems. On the Cisco CyberOps Associate 200-201 exam, this scenario tests your understanding of policy exceptions and risk-based security—a common trap is choosing app passwords as a valid solution, but remember they are a workaround, not a control. The exam expects you to recognize that security policies must adapt to technical limitations without weakening the overall posture. Memory tip: “Legacy apps need a legacy policy—compensate, don’t compromise.”
⚠ Common exam trap
Cisco often tests the misconception that app passwords are a valid second factor, when in reality they are a static bypass that undermines the MFA policy—candidates must recognize that compensating controls are the correct administrative response for unsupported applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a separate policy for legacy applications with compensating controls.
When legacy applications cannot support MFA directly, the best practice is to create a separate policy that documents compensating controls—such as network segmentation, IP allowlisting, or strict access logging—to mitigate the risk of using app passwords. App passwords bypass the second factor and are essentially static credentials, so they must be governed by additional security measures rather than being treated as equivalent to MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow app passwords as they provide a second factor.
Why it's wrong here
App passwords are not true MFA and can bypass the intended security.
- ✗
Implement a VPN requirement for legacy application access.
Why it's wrong here
VPN does not replace MFA; it only secures the connection, not the authentication.
- ✗
Discontinue use of legacy applications until they support MFA.
Why it's wrong here
This may be too disruptive to business operations and not every legacy app can be replaced quickly.
- ✓
Create a separate policy for legacy applications with compensating controls.
Why this is correct
This balances security and business needs by applying additional controls like network isolation and monitoring.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-201
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's security policy states that all employees must use multi-factor authentication (MFA) when accessing the corporate network remotely. Which policy is being applied?
easy- A.Incident Response Policy
- B.Remote Access Policy
- C.Acceptable Use Policy
- ✓ D.Access Control Policy
Why D: Multi-factor authentication (MFA) is an authentication control that falls under the broader category of access controls. The Access Control Policy (D) governs how access to resources is granted and enforced, including authentication mechanisms like MFA. While a Remote Access Policy (B) might address MFA for remote connections, the question directly asks which policy is being applied when requiring MFA for remote network access — this is fundamentally an access control requirement. The other options are incorrect: Incident Response Policy (A) deals with handling security incidents, Acceptable Use Policy (C) defines acceptable behavior, and Remote Access Policy (B) is a subset of access control but not the highest-level policy being applied here.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.