220-1102 Security Practice Question
A company wants to ensure that users must provide two different types of authentication factors when accessing sensitive data. Which term describes this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multifactor authentication
Multifactor authentication (MFA) requires at least two distinct types of evidence, typically something you know (password), something you have (smart card), or something you are (fingerprint). Single sign-on (SSO) allows one credential for multiple services. Role-based access control (RBAC) assigns permissions based on roles. Mandatory Access Control (MAC) uses classification labels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Multifactor authentication
Why this is correct
Multifactor authentication is correct because it explicitly requires two or more independent authentication factors from different categories, such as something you know (password), something you have (security token), or something you are (fingerprint). This prevents a single compromised credential from granting access, since an attacker would need to compromise multiple distinct factor types. The phrase 'two different types' is exactly the definition of MFA, distinguishing it from simply repeating the same kind of credential.
- ✗
Single sign-on
Why it's wrong here
Single sign-on (SSO) is incorrect because it is an authentication architecture designed to let a user authenticate once and then access multiple applications without re-entering credentials. It does not mandate any particular number of factor categories; a password-only SSO session would satisfy SSO but not the requirement for two different types of authentication. While SSO can integrate with MFA at the identity provider, the SSO protocol itself is agnostic about factor diversity.
- ✗
Role-based access control
Why it's wrong here
Role-based access control (RBAC) is incorrect because it addresses what an authenticated user is allowed to do, not how they prove their identity. RBAC assigns permissions dynamically based on organizational roles, so after a user authenticates, they are granted role-appropriate access. It has no built-in mechanism to enforce the use of multiple authentication factors, making it unrelated to the stated requirement.
- ✗
Mandatory Access Control
Why it's wrong here
Mandatory Access Control (MAC) is incorrect because it is a system-level policy that restricts access based on security labels and classifications, such as Top Secret or Secret, for both subjects and objects. MAC operates after authentication and compares labels to determine if a request is permitted, but it does not govern the authentication process itself. Thus, it cannot ensure that a user proves identity via two different factor types.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Common Access Card
A Common Access Card (CAC) is a smart card issued by the U.S. Department of Defense that serves as a single identification, authentication, and access credential for military personnel and contractors.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.