Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: Implementing a new policy that requires users to…

A company is implementing a new policy that requires users to authenticate using both a password and a one-time code sent to their mobile phone. What type of authentication factor is the one-time code?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Something you have

Authentication factors are categorized as something you know (password), something you have (token or phone), and something you are (biometrics). A one-time code sent to a mobile phone is considered 'something you have' because access to the phone is required. This question tests the classification of multi-factor authentication components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Something you are

    Why it's wrong here

    "Something you are" refers to biometric authentication factors, which are unique, inherent physical or behavioral characteristics of an individual. Examples include fingerprints, retina scans, facial recognition, or voice patterns. A one-time code sent to a device does not rely on any intrinsic biological attribute of the user for verification, therefore it does not fall under this category.

  • Something you know

    Why it's wrong here

    "Something you know" authentication factors are secrets that only the legitimate user is supposed to possess and recall, such as a password, PIN, or a security question answer. While a one-time code is 'known' temporarily by the user upon receipt, it is not a pre-established, memorized secret. Its ephemeral nature and method of delivery distinguish it from traditional knowledge-based factors, which are typically static and user-generated or chosen.

  • Something you have

    Why this is correct

    "Something you have" authentication factors rely on the user possessing a specific physical object or device. In this scenario, the one-time code is delivered to a user's phone, which is a tangible item they physically possess and control. The ability to receive and access this code on their device serves as proof of their identity, leveraging the possession of that specific hardware as the authentication factor.

  • Somewhere you are

    Why it's wrong here

    "Somewhere you are" refers to location-based authentication factors, which verify a user's identity based on their geographical position or network location. This could involve GPS coordinates, IP address ranges, or proximity to specific network access points. A one-time code received on a phone, while potentially influenced by the phone's location for delivery, does not inherently verify the user's physical or network presence as the primary authentication mechanism.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.