FC0-U71 Security Practice Question
A company implements a policy requiring employees to use a password and a one-time code sent to their mobile phone when logging into the corporate network. Which security concept is being employed?
⚠ Common exam trap
FC0-U71 often tests security concepts, and candidates might confuse MFA with SSO or RBAC, especially when the scenario involves multiple steps for authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multi-factor authentication
Multi-factor authentication (MFA) requires two or more verification factors to gain access, such as a password (something you know) and a one-time code sent to a mobile phone (something you have). This combination enhances security by adding a layer beyond just a password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control
Why it's wrong here
RBAC governs what an authenticated identity may do via role assignments; it does not verify identity. It is tempting because roles are often granted after login, but the password plus one-time code is multifactor authentication, and RBAC would be correct for authorising access to resources.
- ✗
Single sign-on
Why it's wrong here
Single sign-on lets one authentication event grant access to multiple systems; here each login demands a password and a phone code, with no federation between services. It is tempting because SSO often incorporates MFA, but SSO would be correct if users authenticated once and reached several applications.
- ✓
Multi-factor authentication
Why this is correct
Combining a password (something known) with a one-time code sent to a mobile phone (something possessed) satisfies two distinct authentication factors, which is precisely what multi-factor authentication requires. The policy's two-step login therefore instantiates MFA rather than single-factor or knowledge-based authentication alone.
- ✗
Biometrics
Why it's wrong here
Biometrics verifies identity through a physical characteristic such as a fingerprint or face scan; the scenario uses a password and a phone-delivered one-time code instead. It is tempting because biometrics is also a factor, but it would be correct where a fingerprint reader replaces the password rather than supplementing it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.