Courseiva
Security →hardMultiple Select

220-1102 Security Practice Question

A security administrator is reviewing authentication methods for a company that wants to reduce the risk of credential theft while allowing employees to log in from personal mobile devices. Which two of the following should the administrator implement? (Choose two.)

⚠ Common exam trap

The trap here is selecting SSO or a password manager because they improve password hygiene, while missing that only additional authentication factors stop a stolen password from being used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Biometric authentication

MFA and biometric authentication both add factors that a stolen password alone cannot satisfy, directly reducing the risk of credential theft. SSO, password managers, and RBAC are useful but do not prevent an attacker with stolen credentials from logging in. The administrator should implement MFA and biometric authentication to strengthen login security for personal mobile devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Biometric authentication

    Why this is correct

    Biometric authentication uses a fingerprint, face, or other physical trait as a factor. When used as part of MFA or as a strong authenticator on mobile devices, it makes stolen passwords insufficient for access. It directly reduces the risk of credential theft because the attacker cannot easily replicate the biometric factor.

  • ✗

    Role-based access control (RBAC)

    Why it's wrong here

    RBAC assigns permissions based on job roles, limiting what an authenticated user can do. It does not prevent credential theft or unauthorized login; it only restricts actions after authentication. While valuable for least privilege, it does not address the stated risk of stolen credentials enabling access.

  • ✗

    Single sign-on (SSO)

    Why it's wrong here

    SSO lets users authenticate once and access multiple applications, improving convenience, but it does not by itself reduce the risk of credential theft. If the single credential is compromised, many systems become accessible. SSO should be combined with MFA, but it is not the primary control to implement for this requirement.

  • ✗

    Password manager

    Why it's wrong here

    A password manager helps users create and store strong, unique passwords, which reduces password reuse. However, it does not prevent an attacker who steals the master password or a stored credential from logging in. It is a useful supplement but not a direct defense against credential theft in the way MFA is.

  • ✓

    Multifactor authentication (MFA)

    Why this is correct

    MFA requires a second factor beyond a password, such as a code from an authenticator app or a hardware token. Even if a password is stolen, the attacker cannot log in without the additional factor. This directly reduces the risk of credential theft and is appropriate for logins from personal mobile devices.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.