FC0-U71 Security Practice Question
An organization implements a security policy where users must provide a password and a one-time code generated by a mobile app to log in. Which type of authentication is being used?
⚠ Common exam trap
Candidates often confuse 'token-based authentication' with 'two-factor authentication' — candidates see the mobile app token and pick token-based, forgetting that the password plus OTP together constitute two distinct factors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Two-factor authentication
Two-factor authentication (2FA) requires two different categories of authentication factors: something you know (the password) and something you have (the one-time code generated by the mobile app). Because the password and the OTP come from separate factor classes, this satisfies the definition of 2FA rather than single-factor or a single-category method. The mobile app acts as a soft token, but the overall scheme is still classified as two-factor authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Two-factor authentication
Why this is correct
Combining a knowledge factor (password) with a possession factor (app-generated one-time code) satisfies the stem's two distinct authentication categories. The mobile app produces a time-based code, so compromise of the password alone cannot grant access, meeting the multi-factor requirement.
- ✗
Biometric authentication
Why it's wrong here
The stem describes a password plus a one-time app code, both knowledge/possession factors; no fingerprint, iris or facial trait is verified, so biometric authentication does not apply. It is tempting because biometrics genuinely provides a possession-independent factor, and would be correct if the second factor were a fingerprint scan rather than an app-generated code.
- ✗
Token-based authentication
Why it's wrong here
Token-based authentication describes hardware tokens or issued security tokens, not an app-generated one-time code combined with a password. It is tempting because the mobile app does produce a code resembling a soft token, and would be correct if the question asked specifically about the OTP mechanism rather than the overall authentication type.
- ✗
Single-factor authentication
Why it's wrong here
Two distinct factors are presented — a password (knowledge) and an app-generated one-time code (possession) — so single-factor authentication contradicts the scenario. It is tempting because both credentials are typed into the same login prompt, but that shared interface does not collapse them into one factor; single-factor would be correct for password-only logins.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
8 more ways this is tested on FC0-U71
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company implements a policy where employees must swipe their ID card and then enter a PIN to access the server room. Which two authentication factors are being used?
hardWhy : The ID card is 'something you have' (possession factor) and the PIN is 'something you know' (knowledge factor). This is multi-factor authentication.
Variation 2. Which TWO of the following are examples of multi-factor authentication?
easyWhy : Option A (a smart card and a PIN) is correct because it combines two distinct authentication factors: something you have (the smart card) and something you know (the PIN), which is the definition of multi-factor authentication. Option C (a password and a fingerprint scan) is also correct because it pairs something you know (the password) with something you are (the fingerprint biometric), satisfying MFA's requirement for different factor categories. Option B (two different passwords) is not MFA because both are the same factor type—something you know—so it is merely multi-instance, not multi-factor. Option D (a username and a password) is not MFA because a username is an identifier, not an authentication factor, and the password alone represents a single factor. Option E (a password and a security question) is not MFA because both are knowledge-based factors (something you know), so they belong to the same factor category.
Variation 3. Which THREE of the following are examples of multi-factor authentication? (Select three.)
hardWhy : Multi-factor authentication (MFA) requires combining factors from different categories: something you know (password, PIN), something you have (smart card, phone, token), and something you are (biometrics such as fingerprint or retina scan). Option A is correct because a smart card (something you have) plus a PIN (something you know) combines two distinct factor types. Option B is correct because a password (something you know) plus a fingerprint scan (something you are) also mixes two different factor categories. Option E is correct because a one-time code sent to a phone (something you have) plus a password (something you know) likewise draws on two separate factor types. Option C does not qualify because a retina scan and a fingerprint scan are both biometrics, i.e., two instances of the same 'something you are' factor. Option D does not qualify because a username and password are both 'something you know' and represent a single authentication factor.
Variation 4. Which of the following is an example of something you are in multi-factor authentication?
mediumWhy : In multi-factor authentication, the three factor categories are something you know (password, PIN), something you have (smart card, token, phone), and something you are (biometric — fingerprint, retina, face). A fingerprint scan is a biometric, which falls under 'something you are,' making it the correct example of an 'are' factor.
Variation 5. A company requires employees to use a one-time code from a smartphone app in addition to their password to log into the corporate VPN. This is an example of:
hardWhy : Using a one-time code from a smartphone app in addition to a password combines two different authentication factors: something you know (the password) and something you have (the smartphone app generating the OTP). This satisfies the definition of multi-factor authentication because it uses two distinct factor categories.
Variation 6. An organization implements a security control that requires users to swipe a smart card and then enter a PIN to access a secure facility. Which combination of authentication factors does this represent?
hardWhy : A smart card is a physical token the user possesses, satisfying 'something you have,' while a PIN is a memorized secret, satisfying 'something you know.' Combining these two different factor categories constitutes multi-factor authentication (MFA), which is stronger than single-factor or same-category authentication. This is a classic two-factor physical access control scenario.
Variation 7. An organization requires employees to use a password and a one-time code sent to their mobile phone when logging into the network. Which security principle is being implemented?
mediumWhy : Multi-factor authentication (MFA) requires two or more factors: something you know (password) and something you have (phone).
Variation 8. A company implements a policy requiring employees to use a password and a one-time code sent to their mobile phone when logging into the corporate network. Which security concept is being employed?
mediumWhy : Multi-factor authentication (MFA) requires two or more verification factors to gain access, such as a password (something you know) and a one-time code sent to a mobile phone (something you have). This combination enhances security by adding a layer beyond just a password.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.