220-1102 Security Practice Question
A company has a policy requiring that all employees use multi-factor authentication (MFA) when accessing the corporate VPN. An employee is setting up MFA on their smartphone and is presented with several options. Which of the following MFA methods provides the HIGHEST level of security?
⚠ Common exam trap
CompTIA often tests the misconception that push notifications from an authenticator app are more secure than a hardware token, but the trap here is that push notifications are still software-based and subject to user error and network attacks, whereas a hardware token provides true air-gapped possession-factor security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Time-based one-time password (TOTP) generated by a hardware token
A hardware token generating a time-based one-time password (TOTP) is a possession factor that is not connected to a network or susceptible to remote interception. Unlike software-based methods, the cryptographic seed is stored in a tamper-resistant device, and the code is generated offline using RFC 6238, making it resistant to phishing, SIM swapping, and man-in-the-middle attacks. This provides the highest level of assurance among the listed options.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SMS text message with a one-time code
Why it's wrong here
SMS-based one-time codes travel over the cellular control channel and can be intercepted via SS7 protocol vulnerabilities or obtained by an attacker who successfully performs a SIM-swapping attack, where the mobile carrier ports the victim's phone number to the attacker's SIM. This allows the attacker to receive the code directly, making SMS the least secure choice for MFA.
- ✗
Push notification from an authenticator app
Why it's wrong here
Push authentication relies on the user pressing 'approve' on a separate device, but that device is often the same smartphone used to access the service, and the prompt itself does not contain the context to verify the action. Attackers can exploit MFA fatigue by spamming approval requests until the user accidentally accepts, or use push-notification relay tools to trigger approval during an active login, so the protection depends on user vigilance rather than cryptographic security.
- ✓
Time-based one-time password (TOTP) generated by a hardware token
Why this is correct
A hardware TOTP token generates codes offline from a shared secret embedded in tamper-resistant hardware, and the secret is never exposed over the network or available to intercept via cellular infrastructure. Because the code is dynamic, time-limited, and displayed on a physical device, an attacker cannot redirect it via SIM swap, call forwarding, or a compromised phone app; this provides the highest security among the listed options.
- ✗
Phone call with automated voice code
Why it's wrong here
Delivering a code by automated voice call routes through PSTN/VoIP gateways and shares many of the same weaknesses as SMS, including call-forwarding attacks where the attacker redirects the call to their own number. Additionally, the code is spoken aloud, so an attacker who calls or social-engineers the user into repeating it (vishing) can collect it audibly, making this method substantially less secure than a hardware token.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.