220-1102 Security Practice Question
A security administrator is reviewing authentication methods for a company that wants to reduce the risk of credential theft while allowing employees to log in from personal mobile devices. Which two of the following should the administrator implement? (Choose two.)
⚠ Common exam trap
The trap here is selecting SSO or a password manager because they improve password hygiene, while missing that only additional authentication factors stop a stolen password from being used.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Biometric authentication
MFA and biometric authentication both add factors that a stolen password alone cannot satisfy, directly reducing the risk of credential theft. SSO, password managers, and RBAC are useful but do not prevent an attacker with stolen credentials from logging in. The administrator should implement MFA and biometric authentication to strengthen login security for personal mobile devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Biometric authentication
Why this is correct
Biometric authentication uses a fingerprint, face, or other physical trait as a factor. When used as part of MFA or as a strong authenticator on mobile devices, it makes stolen passwords insufficient for access. It directly reduces the risk of credential theft because the attacker cannot easily replicate the biometric factor.
- ✗
Role-based access control (RBAC)
Why it's wrong here
RBAC assigns permissions based on job roles, limiting what an authenticated user can do. It does not prevent credential theft or unauthorized login; it only restricts actions after authentication. While valuable for least privilege, it does not address the stated risk of stolen credentials enabling access.
- ✗
Single sign-on (SSO)
Why it's wrong here
SSO lets users authenticate once and access multiple applications, improving convenience, but it does not by itself reduce the risk of credential theft. If the single credential is compromised, many systems become accessible. SSO should be combined with MFA, but it is not the primary control to implement for this requirement.
- ✗
Password manager
Why it's wrong here
A password manager helps users create and store strong, unique passwords, which reduces password reuse. However, it does not prevent an attacker who steals the master password or a stored credential from logging in. It is a useful supplement but not a direct defense against credential theft in the way MFA is.
- ✓
Multifactor authentication (MFA)
Why this is correct
MFA requires a second factor beyond a password, such as a code from an authenticator app or a hardware token. Even if a password is stolen, the attacker cannot log in without the additional factor. This directly reduces the risk of credential theft and is appropriate for logins from personal mobile devices.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Audit Logging and Review
Key term
Facial Recognition Technology
Facial recognition technology is a biometric security method that identifies or verifies a person by analyzing and comparing patterns of their facial features.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.