Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

An organization requires employees to use a password and a one-time code sent to their mobile phone when logging into the network. Which security principle is being implemented?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multi-factor authentication

Multi-factor authentication (MFA) requires two or more factors: something you know (password) and something you have (phone).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege limits the permissions an identity holds to those its role requires; it says nothing about how the login is verified. It is tempting because both concern access control, but that is authorisation scope, not authentication strength. The password plus one-time code implements MFA.

  • ✗

    Biometrics

    Why it's wrong here

    Biometrics verifies identity through a physical characteristic such as a fingerprint or face, and no biometric sample is collected here. It is tempting because it is a genuine authentication factor, but it is an inherence factor, whereas the scenario uses knowledge plus possession factors.

  • ✗

    Single sign-on

    Why it's wrong here

    Single sign-on lets one authenticated session reach multiple applications without re-prompting; it does not add a second verification factor. It is tempting because it concerns login convenience, but that is session federation, not factor count. The password plus one-time code implements MFA.

  • ✓

    Multi-factor authentication

    Why this is correct

    Multi-factor authentication combines two distinct credential categories: something the employee knows (the password) and something they possess (the one-time code delivered to their phone). This directly satisfies the stem's requirement for both a password and a phone-based code at login, since possession of the registered device supplies the second, independent authentication factor.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.