Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A company implements a policy requiring employees to use smart cards for authentication. Which security principle does this primarily address?

⚠ Common exam trap

A common mix-up: candidates confuse 'smart card' with 'single sign-on' because smart cards can be used to access multiple resources, but the question specifically asks about the security principle addressed by requiring smart cards for authentication, which is multifactor authentication, not SSO.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multifactor authentication

Smart cards are a form of 'something you have' factor. When combined with a PIN or password (something you know), they satisfy the requirement for multifactor authentication (MFA). The policy primarily addresses MFA because it requires two distinct authentication factors to verify identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Least privilege

    Why it's wrong here

    The principle of least privilege is an authorization control that grants users only the permissions necessary to perform their job functions. Smart cards are an authentication mechanism that verifies who you are, but they do not determine which resources you may access after authentication. Permission levels are still enforced separately by operating system ACLs, group membership, or role-based access control policies. Therefore, implementing smart cards does not directly enforce least privilege on user accounts.

  • ✓

    Multifactor authentication

    Why this is correct

    Smart cards provide a classic example of multifactor authentication (MFA) because they combine two independent factors: something you have (the physical card) and something you know (the PIN or passcode). The device and the PIN are both required to complete authentication, so possessing the card alone is insufficient. This satisfies the policy's requirement for stronger identity verification, making multifactor authentication the correct answer.

  • ✗

    Single sign-on

    Why it's wrong here

    Single sign-on is an authentication process that allows a user to authenticate once and gain access to multiple independent applications or systems without re-entering credentials. Smart cards may be used as a credential store in an SSO environment, but that is a convenience feature rather than the primary security purpose. The policy requirement focuses on verifying an employee's identity with multiple factors, not on reducing password prompts across enterprise applications.

  • ✗

    Account disablement

    Why it's wrong here

    Account disablement is an administrative security control used to deactivate a user's identity, typically when an employee leaves the organization or violates policy, preventing further logon. Smart cards are a credential presented at logon and do not by themselves disable or suspend an Active Directory account. Revoking a smart card's certificate might invalidate the physical token, but that is separate from disabling the underlying user account.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.