FC0-U71 Security Practice Question
A company requires employees to use a one-time code from a smartphone app in addition to their password to log into the corporate VPN. This is an example of:
⚠ Common exam trap
The trap is that candidates may pick 'two-step verification using the same factor' because they see two steps (password + code) and assume both are knowledge factors — but the smartphone app OTP is a possession factor, making this true MFA, not same-factor two-step verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multi-factor authentication
Using a one-time code from a smartphone app in addition to a password combines two different authentication factors: something you know (the password) and something you have (the smartphone app generating the OTP). This satisfies the definition of multi-factor authentication because it uses two distinct factor categories.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Single factor authentication
Why it's wrong here
A password plus a one-time app code combines something you know with something you have, which is multi-factor authentication, not single factor. Single factor is tempting because a password alone is one factor, but adding the app code makes two distinct factors.
- ✓
Multi-factor authentication
Why this is correct
Multi-factor authentication combines something you know (the password) with something you have (the smartphone app generating the one-time code), satisfying the requirement for two distinct credential categories at VPN login. Because the code is time-limited and device-bound, a stolen password alone cannot grant access, which is precisely the layered verification the scenario demands.
- ✗
Two-step verification using the same factor
Why it's wrong here
The scenario pairs a password (knowledge factor) with an app-generated one-time code (possession factor), so two distinct factors are involved, not one. The phrase tempts because SMS and app codes are often loosely called "two-step", but the stem's app code is a separate possession factor.
- ✗
Biometric authentication
Why it's wrong here
A smartphone app code is a possession factor, not a biometric trait such as a fingerprint or iris scan; no physical characteristic is measured here. Biometric authentication would be correct where the second factor is something inherent to the user's body, which the stem does not describe.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.