Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company's multifactor authentication policy requires two different factors. Which of the following combinations satisfies this requirement?

⚠ Common exam trap

The 220-1102 exam often tests the distinction between 'multiple factors' and 'multiple instances of the same factor'—candidates mistakenly think two different biometrics or two different knowledge items count as multifactor, but they must come from different categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fingerprint and password

It combines something you are (fingerprint, a biometric factor) with something you know (password, a knowledge factor). Multifactor authentication requires factors from at least two different categories: knowledge, possession, or inherence. A fingerprint and password satisfy this requirement by using two distinct factor types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Smart card and username

    Why it's wrong here

    A smart card is a possession factor (something you have), but a username is merely an identifier, not an authentication factor; it claims who you are rather than proving it. Consequently, this combination supplies only one factor, and any attacker who steals the smart card (or uses a cloned card) still only needs that single token to authenticate, failing the requirement for multifactor authentication.

  • ✗

    Password and security question

    Why it's wrong here

    Both a password and a security question are knowledge factors (something you know). The security question's answer, despite often being personal information, is still knowledge-based and does not introduce a second authentication category. Therefore, this pair offers no additional factor diversity and remains single-factor authentication, vulnerable to phishing or credential-stuffing attacks that compromise the knowledge layer.

  • ✓

    Fingerprint and password

    Why this is correct

    A fingerprint is an inherence factor (something you are) tied to a physical biometric characteristic, while a password is a knowledge factor (something you know). Combining these two distinct categories meets the definition of multifactor authentication, because an attacker would need to both possess the user's fingerprint (or a convincing biometric spoof) and know the password, significantly raising the bar against unauthorized access.

  • ✗

    Retina scan and voice recognition

    Why it's wrong here

    A retina scan and voice recognition are both biometric, inherence factors (something you are), even though they measure different body parts or traits. Authenticating with two different biometric modalities still relies on the same factor category, so it is not multifactor authentication; it is essentially a more elaborate form of single-factor authentication. If either biometric is compromised, the attacker can satisfy both checks simultaneously.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.