Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company wants to implement multi-factor authentication (MFA) for remote access to its VPN. Which of the following combinations represents a valid MFA setup?

⚠ Common exam trap

Many candidates confuse 'multiple authentication steps' with 'multi-factor authentication,' mistakenly thinking two items from the same category (e.g., two biometrics or two passwords) qualify as MFA, when in fact MFA requires factors from at least two different categories (knowledge, possession, inherence).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smart card and PIN

Multi-factor authentication (MFA) requires two or more factors from different categories: something you know (PIN), something you have (smart card), and/or something you are. A smart card (possession factor) combined with a PIN (knowledge factor) satisfies this requirement, as each factor belongs to a distinct authentication category, providing stronger security for VPN remote access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password and security question

    Why it's wrong here

    A password and a security question both fall into the same authentication category: something the user knows. MFA requires two distinct factor types (e.g., knowledge plus possession), so combining two knowledge-based secrets does not raise assurance above single-factor authentication. Security answers also tend to be weaker because they are often guessable or sourced from public data, but the fundamental flaw is the redundant factor category.

  • ✓

    Smart card and PIN

    Why this is correct

    This is a legitimate MFA combination because it uses two independent factors: the smart card is something you have (a possession factor storing cryptographic credentials), and the PIN is something you know (a knowledge factor). The card alone is useless without the PIN, and the PIN alone cannot authenticate without the card's secret key, so an attacker must compromise both a physical device and a secret. This mutual dependency defeats phishing and credential-theft attacks better than password-only systems.

  • ✗

    Fingerprint and retina scan

    Why it's wrong here

    A fingerprint and a retina scan are both biometric identifiers, meaning they both belong to the 'something you are' factor category. MFA does not count different techniques within the same category; it requires factors from different categories, such as knowledge, possession, and inherence. Requiring two separate biometric checks may increase accuracy but does not change the fact that an attacker who steals your biometric data once has both credentials.

  • ✗

    Password and username

    Why it's wrong here

    A password and a username are not two independent factors: the username is simply an identifier rather than a secret, and the password is the only credential presented. Since both are knowledge-based (the username is usually public or easily guessed), this setup still provides only single-factor authentication. MFA would require adding a second factor type, such as a hardware token (possession) or biometric (inherence), rather than merely appending an identifier.

Go deeper

Related to this question

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.