Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company has a policy requiring that all employees use multi-factor authentication (MFA) when accessing the corporate VPN. An employee is setting up MFA on their smartphone and is presented with several options. Which of the following MFA methods provides the HIGHEST level of security?

⚠ Common exam trap

CompTIA often tests the misconception that push notifications from an authenticator app are more secure than a hardware token, but the trap here is that push notifications are still software-based and subject to user error and network attacks, whereas a hardware token provides true air-gapped possession-factor security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Time-based one-time password (TOTP) generated by a hardware token

A hardware token generating a time-based one-time password (TOTP) is a possession factor that is not connected to a network or susceptible to remote interception. Unlike software-based methods, the cryptographic seed is stored in a tamper-resistant device, and the code is generated offline using RFC 6238, making it resistant to phishing, SIM swapping, and man-in-the-middle attacks. This provides the highest level of assurance among the listed options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SMS text message with a one-time code

    Why it's wrong here

    SMS-based one-time codes travel over the cellular control channel and can be intercepted via SS7 protocol vulnerabilities or obtained by an attacker who successfully performs a SIM-swapping attack, where the mobile carrier ports the victim's phone number to the attacker's SIM. This allows the attacker to receive the code directly, making SMS the least secure choice for MFA.

  • ✗

    Push notification from an authenticator app

    Why it's wrong here

    Push authentication relies on the user pressing 'approve' on a separate device, but that device is often the same smartphone used to access the service, and the prompt itself does not contain the context to verify the action. Attackers can exploit MFA fatigue by spamming approval requests until the user accidentally accepts, or use push-notification relay tools to trigger approval during an active login, so the protection depends on user vigilance rather than cryptographic security.

  • ✓

    Time-based one-time password (TOTP) generated by a hardware token

    Why this is correct

    A hardware TOTP token generates codes offline from a shared secret embedded in tamper-resistant hardware, and the secret is never exposed over the network or available to intercept via cellular infrastructure. Because the code is dynamic, time-limited, and displayed on a physical device, an attacker cannot redirect it via SIM swap, call forwarding, or a compromised phone app; this provides the highest security among the listed options.

  • ✗

    Phone call with automated voice code

    Why it's wrong here

    Delivering a code by automated voice call routes through PSTN/VoIP gateways and shares many of the same weaknesses as SMS, including call-forwarding attacks where the attacker redirects the call to their own number. Additionally, the code is spoken aloud, so an attacker who calls or social-engineers the user into repeating it (vishing) can collect it audibly, making this method substantially less secure than a hardware token.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.