220-1102 Security Practice Question
A security administrator is evaluating authentication methods. Which of the following is NOT an example of multifactor authentication?
⚠ Common exam trap
The trap here is that candidates mistakenly believe that using any two different authentication methods automatically constitutes MFA, but CompTIA tests the strict definition that the methods must come from at least two different factor categories (knowledge, possession, inherence), not just be different technologies within the same category.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A fingerprint scan and a retina scan
Multifactor authentication (MFA) requires at least two different factors from the categories: something you know (knowledge), something you have (possession), and something you are (inherence). Option C uses two biometric factors (fingerprint scan and retina scan), both falling under 'something you are,' which constitutes only a single factor type, not MFA. True MFA must combine factors from at least two distinct categories.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A password and a fingerprint scan
Why it's wrong here
A password is a knowledge factor (something you know), whereas a fingerprint scan is an inherence factor (something you are). Because the two credentials come from different factor categories, this combination satisfies the definition of multifactor authentication and therefore is not the exception the question asks for. Even if both are required at login, the system is validating two independent types of proof.
- ✗
A smart card and a PIN
Why it's wrong here
A smart card is a possession factor because it is a physical token the user must have, while the PIN is a knowledge factor because it is a secret the user must know. The card and PIN are separate, independently derived factor categories, making this a legitimate two-factor authentication mechanism. This combination is common in PIV/CAC deployments but still qualifies as MFA, so it does not match the question's 'not MFA' answer.
- ✓
A fingerprint scan and a retina scan
Why this is correct
This is the correct answer because a fingerprint scan and a retina scan are both biometric modalities that fall under the same factor category: something you are (inherence). Though the enrollment and matching processes differ, the system is only using one class of evidence—biological characteristics—so it is single-factor authentication using two methods of the same factor. Multifactor authentication requires two or more independent factor categories, not simply multiple credentials from the same category.
- ✗
A password and a SMS one-time code
Why it's wrong here
A password is something the user knows, and the one-time code sent via SMS is something the user has, because delivery to the registered phone demonstrates possession of that device or SIM. Even though the user types the code, the security strength comes from combining a knowledge factor with a possession factor. Therefore this is an MFA arrangement, not the single-factor exception asked for, despite SMS-based OTP being a weaker possession proof than app-generated codes.
Go deeper
Related to this question
Learn chapter
Principle of Least Privilege
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.