Courseiva
SecurityhardMultiple ChoiceObjective-mapped

FC0-U71 Security Practice Question

An organization implements a security policy where users must provide a password and a one-time code generated by a mobile app to log in. Which type of authentication is being used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Two-factor authentication

Multi-factor authentication requires two or more factors from different categories: something you know (password), something you have (smartphone app generating a code), and something you are (biometric).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Two-factor authentication

    Why this is correct

    Two factors are used: password (knowledge) and code from device (possession).

  • Biometric authentication

    Why it's wrong here

    Biometric uses physical characteristics like fingerprints, not a code.

  • Token-based authentication

    Why it's wrong here

    Token-based can be part of MFA, but the combination described is specifically two-factor.

  • Single-factor authentication

    Why it's wrong here

    Single-factor uses only one factor, such as a password.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

8 more ways this is tested on FC0-U71

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company implements a policy where employees must swipe their ID card and then enter a PIN to access the server room. Which two authentication factors are being used?

hard
  • A.Something you know and something you are
  • B.Something you have and something you are
  • C.Something you have and something you know
  • D.Something you know and somewhere you are

Why C: The ID card is 'something you have' (possession factor) and the PIN is 'something you know' (knowledge factor). This is multi-factor authentication.

Variation 2. Which TWO of the following are examples of multi-factor authentication?

easy
  • A.A smart card and a PIN
  • B.Two different passwords
  • C.A password and a fingerprint scan
  • D.A username and a password
  • E.A password and a security question

Why A: Multi-factor authentication requires two or more different types of authentication factors.

Variation 3. Which THREE of the following are examples of multi-factor authentication? (Select three.)

hard
  • A.A smart card and a PIN
  • B.A password and a fingerprint scan
  • C.A retina scan and a fingerprint scan
  • D.A username and password
  • E.A one-time code sent to a phone and a password

Why A: MFA requires two or more different factors: something you know, something you have, and something you are. Each correct answer uses at least two distinct factors.

Variation 4. Which of the following is an example of something you are in multi-factor authentication?

medium
  • A.Password
  • B.Fingerprint scan
  • C.Smart card
  • D.One-time passcode

Why B: Biometrics (fingerprint, face) are physical characteristics, i.e., something you are.

Variation 5. A company requires employees to use a one-time code from a smartphone app in addition to their password to log into the corporate VPN. This is an example of:

hard
  • A.Single factor authentication
  • B.Multi-factor authentication
  • C.Two-step verification using the same factor
  • D.Biometric authentication

Why B: Multi-factor authentication (MFA) combines something you know (password) and something you have (smartphone app generating a code). This is MFA.

Variation 6. An organization implements a security control that requires users to swipe a smart card and then enter a PIN to access a secure facility. Which combination of authentication factors does this represent?

hard
  • A.Something you are and something you have
  • B.Something you know and something you do
  • C.Something you have and something you know
  • D.Something you know and something you are

Why C: Smart card is 'something you have' and PIN is 'something you know', making it two-factor authentication using different factor types.

Variation 7. An organization requires employees to use a password and a one-time code sent to their mobile phone when logging into the network. Which security principle is being implemented?

medium
  • A.Least privilege
  • B.Biometrics
  • C.Single sign-on
  • D.Multi-factor authentication

Why D: Multi-factor authentication (MFA) requires two or more factors: something you know (password) and something you have (phone).

Variation 8. A company implements a policy requiring employees to use a password and a one-time code sent to their mobile phone when logging into the corporate network. Which security concept is being employed?

medium
  • A.Role-based access control
  • B.Single sign-on
  • C.Multi-factor authentication
  • D.Biometrics

Why C: Multi-factor authentication (MFA) requires two or more factors: something you know (password) and something you have (phone).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.