Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

A company implements a policy requiring employees to use a password and a one-time code sent to their mobile phone when logging into the corporate network. Which security concept is being employed?

⚠ Common exam trap

FC0-U71 often tests security concepts, and candidates might confuse MFA with SSO or RBAC, especially when the scenario involves multiple steps for authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multi-factor authentication

Multi-factor authentication (MFA) requires two or more verification factors to gain access, such as a password (something you know) and a one-time code sent to a mobile phone (something you have). This combination enhances security by adding a layer beyond just a password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-based access control

    Why it's wrong here

    RBAC governs what an authenticated identity may do via role assignments; it does not verify identity. It is tempting because roles are often granted after login, but the password plus one-time code is multifactor authentication, and RBAC would be correct for authorising access to resources.

  • ✗

    Single sign-on

    Why it's wrong here

    Single sign-on lets one authentication event grant access to multiple systems; here each login demands a password and a phone code, with no federation between services. It is tempting because SSO often incorporates MFA, but SSO would be correct if users authenticated once and reached several applications.

  • ✓

    Multi-factor authentication

    Why this is correct

    Combining a password (something known) with a one-time code sent to a mobile phone (something possessed) satisfies two distinct authentication factors, which is precisely what multi-factor authentication requires. The policy's two-step login therefore instantiates MFA rather than single-factor or knowledge-based authentication alone.

  • ✗

    Biometrics

    Why it's wrong here

    Biometrics verifies identity through a physical characteristic such as a fingerprint or face scan; the scenario uses a password and a phone-delivered one-time code instead. It is tempting because biometrics is also a factor, but it would be correct where a fingerprint reader replaces the password rather than supplementing it.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.