hardMultiple Choice
MFA Policy for Legacy Applications
A company is implementing a security policy that requires all employees to use multi-factor authentication (MFA) when accessing corporate resources remotely. However, during a recent security audit, it was found that several employees have been using app passwords for legacy applications that do not support MFA. What is the best practice under this policy?
Quick Answer
The correct answer is to create a separate policy for legacy applications with compensating controls. This is because app passwords, while allowing legacy apps to bypass MFA, are essentially static credentials that do not satisfy true multi-factor authentication and can be exploited if stolen. A separate policy for legacy applications should enforce compensating controls such as network segmentation, strict monitoring, and conditional access to mitigate the risk without forcing the immediate retirement of critical but outdated systems. On the Cisco CyberOps Associate 200-201 exam, this scenario tests your understanding of policy exceptions and risk-based security—a common trap is choosing app passwords as a valid solution, but remember they are a workaround, not a control. The exam expects you to recognize that security policies must adapt to technical limitations without weakening the overall posture. Memory tip: “Legacy apps need a legacy policy—compensate, don’t compromise.”
⚠ Common exam trap
Cisco often tests the misconception that app passwords are a valid second factor, when in reality they are a static bypass that undermines the MFA policy—candidates must recognize that compensating controls are the correct administrative response for unsupported applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a separate policy for legacy applications with compensating controls.
When legacy applications cannot support MFA directly, the best practice is to create a separate policy that documents compensating controls—such as network segmentation, IP allowlisting, or strict access logging—to mitigate the risk of using app passwords. App passwords bypass the second factor and are essentially static credentials, so they must be governed by additional security measures rather than being treated as equivalent to MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow app passwords as they provide a second factor.
Why it's wrong here
App passwords are single static credentials generated once and reused indefinitely, so they supply no second factor and directly violate the MFA requirement. It is tempting because app passwords exist precisely to let legacy clients that cannot present MFA prompts authenticate, which is why they are a known policy exception to remediate.
- ✗
Implement a VPN requirement for legacy application access.
Why it's wrong here
A VPN tunnels network traffic but does not add a second authentication factor, so app passwords remain the sole credential and the MFA policy is still bypassed. It is tempting because VPNs genuinely secure remote transport and are correct when the requirement is encrypted access to internal networks rather than stronger authentication.
- ✗
Discontinue use of legacy applications until they support MFA.
Why it's wrong here
App passwords exist precisely to let legacy applications bypass MFA, so the policy's intent is defeated while those credentials remain valid. Discontinuing the applications outright halts business processes that may have no MFA-capable replacement. The correct approach is to remove or block app passwords and migrate those applications to modern authentication.
- ✓
Create a separate policy for legacy applications with compensating controls.
Why this is correct
Legacy applications lacking MFA support cannot enforce the policy directly, so a distinct policy with compensating controls—such as IP restrictions, conditional access in Microsoft Entra ID, or monitored app passwords—isolates their risk without weakening MFA enforcement elsewhere. This satisfies the audit finding while maintaining the remote-access security requirement.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-201
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's security policy states that all employees must use multi-factor authentication (MFA) when accessing the corporate network remotely. Which policy is being applied?
easy- A.Incident Response Policy
- B.Remote Access Policy
- C.Acceptable Use Policy
- ✓ D.Access Control Policy
Why D: The Access Control Policy defines the rules for how users are authenticated and authorized to access systems and data. Requiring MFA for remote access is a specific access control mechanism that enforces who can connect and under what conditions. While a Remote Access Policy might also mention MFA, the core of the requirement is about controlling access to resources, making Access Control Policy the best fit. The policy is not about incident response, acceptable use, or remote access procedures in general.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.