FC0-U71 Security Practice Question
An organization requires employees to use a password and a one-time code sent to their mobile phone when logging into the network. Which security principle is being implemented?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multi-factor authentication
Multi-factor authentication (MFA) requires two or more factors: something you know (password) and something you have (phone).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege
Why it's wrong here
Least privilege limits the permissions an identity holds to those its role requires; it says nothing about how the login is verified. It is tempting because both concern access control, but that is authorisation scope, not authentication strength. The password plus one-time code implements MFA.
- ✗
Biometrics
Why it's wrong here
Biometrics verifies identity through a physical characteristic such as a fingerprint or face, and no biometric sample is collected here. It is tempting because it is a genuine authentication factor, but it is an inherence factor, whereas the scenario uses knowledge plus possession factors.
- ✗
Single sign-on
Why it's wrong here
Single sign-on lets one authenticated session reach multiple applications without re-prompting; it does not add a second verification factor. It is tempting because it concerns login convenience, but that is session federation, not factor count. The password plus one-time code implements MFA.
- ✓
Multi-factor authentication
Why this is correct
Multi-factor authentication combines two distinct credential categories: something the employee knows (the password) and something they possess (the one-time code delivered to their phone). This directly satisfies the stem's requirement for both a password and a phone-based code at login, since possession of the registered device supplies the second, independent authentication factor.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.