Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company's security policy requires all employees to use multi-factor authentication (MFA) when accessing the corporate VPN. An employee uses a smart card (something you have) and a PIN (something you know). Which of the following is true about this MFA implementation?

⚠ Common exam trap

It's easy for candidates to confuse 'two steps' with 'two factors' — they may think that because the PIN is used to unlock the smart card, it is not a separate factor, but MFA only requires factors from different categories, not that they be used independently or in a specific order.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

This is MFA because it uses two different authentication factors: something you have and something you know.

Multi-factor authentication (MFA) requires the use of two or more distinct authentication factors. A smart card is a physical device, which falls under 'something you have', and a PIN is a secret known only to the user, which falls under 'something you know'. Since these are two different categories of authentication factors, this implementation satisfies the definition of MFA, regardless of whether the PIN is used to unlock the smart card or is entered separately.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    This is not MFA because the smart card and PIN are both considered 'something you have'.

    Why it's wrong here

    The assertion misclassifies both credentials as possession factors. In fact, the smart card is a hardware token in the 'something you have' category, while the PIN is a memorized secret in the 'something you know' category. Because the system requires both a possession factor and a knowledge factor, this is true MFA, not single-factor authentication. The claim is therefore incorrect.

  • ✓

    This is MFA because it uses two different authentication factors: something you have and something you know.

    Why this is correct

    This is genuinely multi-factor authentication because it combines two distinct factor types: the physical smart card proves possession, and the PIN proves knowledge. The system cannot authenticate the user without both, so compromising either alone does not grant access. That combination meets the accepted definition of MFA, regardless of how the PIN is used internally.

  • ✗

    This is MFA only if the PIN is also used to unlock the smart card.

    Why it's wrong here

    Requiring the PIN to unlock the smart card is an implementation detail, not a necessary condition for MFA. The PIN is already an independent knowledge factor layered on top of the possession factor, so the authentication remains MFA whether or not the card stores a cryptographic key released by the PIN. Adding the unlock step does not increase or change the factor count. The statement's conditional is therefore false.

  • ✗

    This is not MFA because the same PIN can be used with multiple smart cards.

    Why it's wrong here

    MFA classification depends on the types of factors used, not on the uniqueness or secrecy of the PIN value. Even if multiple users share the same PIN, the user still must physically present the card (something you have) and supply the PIN (something you know). Reusable or weak PINs may undermine security, but they do not collapse the authentication into a single factor. Thus the conclusion that it is not MFA is incorrect.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company's multifactor authentication policy requires two different factors. Which of the following combinations satisfies this requirement?

medium
  • A.Smart card and username
  • B.Password and security question
  • ✓ C.Fingerprint and password
  • D.Retina scan and voice recognition

Why C: It combines something you are (fingerprint, a biometric factor) with something you know (password, a knowledge factor). Multifactor authentication requires factors from at least two different categories: knowledge, possession, or inherence. A fingerprint and password satisfy this requirement by using two distinct factor types.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.