mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: Implementing a new policy that requires users to…
A company is implementing a new policy that requires users to authenticate using both a password and a one-time code sent to their mobile phone. What type of authentication factor is the one-time code?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Something you have
Authentication factors are categorized as something you know (password), something you have (token or phone), and something you are (biometrics). A one-time code sent to a mobile phone is considered 'something you have' because access to the phone is required. This question tests the classification of multi-factor authentication components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Something you are
Why it's wrong here
"Something you are" refers to biometric authentication factors, which are unique, inherent physical or behavioral characteristics of an individual. Examples include fingerprints, retina scans, facial recognition, or voice patterns. A one-time code sent to a device does not rely on any intrinsic biological attribute of the user for verification, therefore it does not fall under this category.
- ✗
Something you know
Why it's wrong here
"Something you know" authentication factors are secrets that only the legitimate user is supposed to possess and recall, such as a password, PIN, or a security question answer. While a one-time code is 'known' temporarily by the user upon receipt, it is not a pre-established, memorized secret. Its ephemeral nature and method of delivery distinguish it from traditional knowledge-based factors, which are typically static and user-generated or chosen.
- ✓
Something you have
Why this is correct
"Something you have" authentication factors rely on the user possessing a specific physical object or device. In this scenario, the one-time code is delivered to a user's phone, which is a tangible item they physically possess and control. The ability to receive and access this code on their device serves as proof of their identity, leveraging the possession of that specific hardware as the authentication factor.
- ✗
Somewhere you are
Why it's wrong here
"Somewhere you are" refers to location-based authentication factors, which verify a user's identity based on their geographical position or network location. This could involve GPS coordinates, IP address ranges, or proximity to specific network access points. A one-time code received on a phone, while potentially influenced by the phone's location for delivery, does not inherently verify the user's physical or network presence as the primary authentication mechanism.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Mobile OS Issues
Key term
Multifactor Authentication
Multifactor Authentication (MFA) is a security method that requires you to provide two or more pieces of evidence to prove your identity before accessing an account or system.
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.